Skip to content

UCCA Canon Register (living)

What this is. The maintained list of the UCCA project's true documents, so canon can't quietly drift or duplicate. This is the living successor to UCCA-CAPTURE-01 §4 — where CAPTURE §4 is the historical snapshot of the 2026-07-01 filing plan, this register states what is actually on disk now. Register rule: never claim ✓ without a file. A row is filed ✓ only if the byte path exists in this repo.

Status vocabulary (per UCCA-ADR-LIFECYCLE-01). Rulings/ADRs carry a lifecycle class and state — a ruling binds when Tim rules; minting is an honesty marker about proof, not a permission gate: ruled (B, pre-proof) · minted (F, verified <date>) · minted (G, ratified <date>). Class F = record of existing fact (mints on verification); Class B = forward build ruling (mints at build proof); Class G = governance convention (mints on ratification).

Filing principle (CAPTURE §3): a document's home is decided by how often it changes, not by topic.

Canon — written to be true

doc_id title status path
UCCA-TM-2026-07-18-D Tech-status Time Machine (2026-07-18, close baton — CORRECTED) — CURRENT REFERENCE. CAP-1 ID-fork ruling banked + v1.1 schema clarification live (engine 7137e26, docs cb31a38), THEN CAP-1 + CAP-2 BUILT — Units 1–4 shipped (e722cfc47ea49e), 5/5 offline, additive (372/+4−), no D1 migration — but NOT MINTED (no deploy, no seal proof; gated on the A1 live-deploy read). Fence: TWO crossings in flight (C-6 + CAP-1, FI-04) — assert from the fence log. Corrected reissue of the 11:41 UTC pre-GO draft (which said 'nothing built' — discarded, never filed; caught stale at filing). Supersedes UCCA-TM-2026-07-18-C on the CAP-1 deltas + fence count; 18-C's base layer stands. filed ✓ 2026-07-18 (relayed by Tim, verified on bytes: HEADs + diff-stat + 5/5 tests; sha256 8182e222d09a655de58902449d5ef4246745175a7c5e6c958324cb31695bb076) ground/UCCA-TM-2026-07-18-D.md
UCCA-TM-2026-07-18-C Tech-status Time Machine (2026-07-18, consolidation baton) — the stable BASE layer 18-D builds on (app + credential threads reconciled). Filed via delivery slip (docs 88b937c); registered here retroactively for chain integrity. Superseded as reference by 18-D on the CAP-1 deltas + fence count; its base layer otherwise stands. filed ✓ 2026-07-18 ground/UCCA-TM-2026-07-18-C.md
UCCA-TM-2026-07-18-B Tech-status Time Machine (2026-07-18, afternoon) — CURRENT REFERENCE. Code substrate unchanged since 16 Jul (engine bc5b820 · docs 2eaea3d · surfaces b162308 · infra b00603f · tools 94aecca). Delta: 1Password store now READ+WRITE via new SA ucca-automation-rw (2K5UOFYL…), Android upload keystore FILED + round-trip verified (item kwskgazx…). Three items owed (KEY_SERVER_SECRET conflict · confirm Play App Signing com.ucca.online · delete orphan read-only SAs) — none block build. Never-export-the-token rule reaffirmed (RTOpacks SA also on machine). Supersedes UCCA-TM-2026-07-18-A as the reference (per R-TM, -A keeps its morning text + forward-banner). filed ✓ 2026-07-18 (authored + filed in-workspace; sha256 19d23d598575b6259f3858d1db294d59c1d53d4b417f0a8d43746c96b69d9d74) ground/UCCA-TM-2026-07-18-B.md
UCCA-FOUNDATION-01 what the engine is filed ✓ (§4 corrected per ADR-0001 at filing) canon/UCCA-FOUNDATION-01.md
UCCA-FENCE-ADOPTION-01 home-side adoption of FENCE-PROTOCOL-01 filed ✓ · minted (G, ratified 2026-07-01) canon/UCCA-FENCE-ADOPTION-01.md
UCCA-ADR-LIFECYCLE-01 when a ruling becomes an ADR filed ✓ · minted (G, ratified 2026-07-01) canon/UCCA-ADR-LIFECYCLE-01.md
UCCA-NORTHSTAR-01 the universal engine / single throat / vision as build-constraint RATIFIED canon 2026-07-02 ✓ (Class G — minted on ratification; §4 seed byte-verified vs CAPTURE-01 §7) ✎ v1.1 amended 2026-07-24 (Class G, Tim) — §1 compiled-normal-form + honest instrument-scope; new §6 the declared claim. Ruling UCCA-AMENDMENT-NORTHSTAR-HONESTY-2026-07-24. ✎ v1.2 amended 2026-07-26 (Class G, Tim) — §6 completed with the claim's content: TRACED = anchored responsiveness with named exclusions, never satisfaction; NOT_YET_TRACED = honest gap, never non-compliance. Ratifies the 2026-07-19 scoping. Ruling UCCA-AMENDMENT-NORTHSTAR-TRACED-SEMANTICS-2026-07-26. canon/UCCA-NORTHSTAR-01.md
UCCA-INTAKE-01 engine terms + client intake (warranty on the envelope, offboarding by clearance discipline) RATIFIED 2026-07-03 (UCCA-RATIFICATION-INTAKE-01; Class G minted on ratification) — the engine's standing client-facing terms ground/UCCA-INTAKE-01.md

Ground — true today

doc_id title status path
UCCA-RUN-BRIEF-MODEL-SWITCHER-2026-07-27 Run brief — the model-switcher proof (Model B @cf/nvidia/nemotron-3-120b-a12b) + the cost-probe pricing pass. Proves on sealed records that the engine's honesty behaviour survives a model swap — that the throat is model-neutral in fact, not only in code — and mints the per-model calibration law: no model's verdicts carry weight until that model has its own calibration read under the ruled semantics; a record is evidence about one (model, suite, fence_version) triple and never about "the engine" in the abstract. Scope ruled "Proof + price the field" — full proof on nemotron only, one cost probe each across the reasoning-capable candidates. Six seams; Seam 0 is report-then-pick on the trigger path. States, not scores. RULED 2026-07-27 by Tim, as drafted — EXECUTED END TO END. Machinery built and shipped: engine 62066d4 (Seams 1–3) → 9e40c15 (marker bump; container v33, image sha256:1a63afca…, rollout completed) · surfaces 4e4e993 (admin-api forwards model + /costprobe/run). Cost probes both models, seven mirrored triggers from Tim's hand, verdict UCCA-VERDICT-MODEL-SWITCHER-2026-07-27 (b5097b6e…). Class B for the switcher machinery MINTS on this run proof — the throat is model-neutral in fact, not only in code. Bytes carry status: DRAFT v0.1; rulings live in this row. Verifies to 82765bea…, 89 lines. ground/UCCA-RUN-BRIEF-MODEL-SWITCHER-2026-07-27.md
UCCA-VERDICT-MODEL-SWITCHER-2026-07-27 Verdict — the model-switcher proof, read under the pre-registration v0.2. Fourteen sealed records (seven GLM-5.2 baseline · seven nemotron-3-120b mirror, 126 elements each) read per-element on the pre-registered dimensions only. The honesty discipline SURVIVED the swap: a maximally-different lab's model held the full output contract, anchored every claim, and broke the live v1.1 fence zero times in 126 elements — TRACED-means-anchored and NOT_YET-means-honest-gap behaved identically as discipline on both models. The two models' calibration signatures are OPPOSITE and that is the finding, not a defect: GLM's errors and instability point toward over-claim, nemotron's toward under-claim (3 declined legitimate TRACEDs, 1 flip toward NOT_YET, one stable over-claim site). Demonstrates the per-model calibration law on bytes. The corpus's under-claim blindness is re-confirmed load-bearing — visible here only because those probes are verbatim-class; the bridge suite is where it becomes measurable. Cost 0.647× at suite scale, 2.4× faster on the probe pair, billing visible via neurons on both. ISSUED 2026-07-27 on triple-hashed bytes (R2 exact-key fetch → verdict-drop-2026-07-27/ → MANIFEST b7068795… → re-hash; all 14 digests matched Alex's attestation, no drift). Burst deviation declared on its face with Tim's ruling. TIM RULED GATE C CLOSED on this document. Quotes no accuracy as quality; ranks no model; selects nothing for service — the serving default remains the pinned GLM-5.2 constant. Verifies to b5097b6e…, 63 lines. ground/UCCA-VERDICT-MODEL-SWITCHER-2026-07-27.md
UCCA-LAW-PER-MODEL-CALIBRATION-01 The per-model calibration law. Wording per UCCA-RUN-BRIEF-MODEL-SWITCHER-2026-07-27 §2, verbatim: "No model's verdicts carry weight until that model has its own calibration read under the ruled semantics. A calibration record is evidence about one (model, suite, fence_version) triple — never about 'the engine' in the abstract and never about any other model." The record schema already carried the triple (model · probe_set_version · fence_version); the law makes the discipline standing rather than accidental. Demonstrated on bytes the same day: two models, one throat, one fence, opposite calibration signatures — which is precisely why a record may not be read across models. MINTED Class G — ratified 2026-07-27 by Tim with the brief's tick, carried into canon at this close relay. Law text lives in the brief's filed bytes (82765bea… §2); this row is its register entry. ground/UCCA-RUN-BRIEF-MODEL-SWITCHER-2026-07-27.md §2
UCCA-MODEL-RECON-2026-07-27 Workers AI reasoning-model recon — dated rows, read 2026-07-27T07:05:37Z. The eleven reasoning-capable text-generation models enumerable on e5a98302 via the Cloudflare REST API (26 of 61 are text-gen; 11 of those carry reasoning: true), with context window, function-calling, vision, async-queue and USD/M list prices. Successor row-set to UCCA-MODEL-CENSUS-01 (2026-07-05) — additive, no rewrite. These eleven ids ARE MEASUREMENT_MODEL_ALLOWLIST in reasoner/consumer.py, verified identical by AST parse at filing — list and artefact match by construction. Gaps are stated, not filled: neurons absent from the endpoint, reasoning-token behaviour absent, no deprecation field, and total_count reports 279 while only 61 are servable. Carries the standing warning list price ≠ cost forecast on reasoning models. filed ✓ (Ground; dated read) — Seam 5 of UCCA-RUN-BRIEF-MODEL-SWITCHER-2026-07-27; the recon was Alex-attested-only until this filing, now an artefact ground/UCCA-MODEL-RECON-2026-07-27.md
UCCA-NOTE-RUN-PREREGISTRATION-SWITCHER-2026-07-27 Pre-registration — the switcher proof runs (nemotron-3-120b mirroring the seven-suite GLM-5.2 baseline). Fixes the reading rules, the baseline keys, the trigger discipline and the stop rules before any nemotron record exists — the whole point of filing it now. Carries the drafter-owned correction to the run brief §5.2–5.3: the sealed ruled-semantics baseline is the seven per-suite records of 2026-07-27, not v2; the proof mirrors that pass and v2 appears nowhere. Reading is the (suite, element) pair on five named dimensions — fence behaviour first, repair counts excluded (repair_used is honest-null by accident at engine 9e40c15). Four stop rules incl. a third failures/ object and any fence_version ≠ v1.1. §7 declares the drafter's conflict before the records exist. FILED — TICKED by Tim 2026-07-27, v0.2, BEFORE trigger one. Supersedes draft v0.1 (5f80255d…) — v0.1 not filed, by ruling. Bytes carry status: DRAFT v0.2; the tick lives in this row. The verdict on the runs may read only what this document names. Verifies to 11594f56…, 72 lines. ✎ §3 deviation ruled 2026-07-27 (Tim): 'Records stand, burst declared.' Seven triggers went out inside 51 s without seal confirmation; the single-flight lock refused five (already_running), records 08:59:41.229Z and 09:04:12.784Z sealed alone inside that window, and the five missing suites completed one-at-a-time after Alex's flag. No re-run. The deviation is carried on the verdict's face. ground/UCCA-NOTE-RUN-PREREGISTRATION-SWITCHER-2026-07-27.md
UCCA-RESUME-BRIEF-BRIDGE-SUITE-2026-07-28 Resume brief — the bridge suite (hard true positives), resumed under NORTHSTAR v1.2. Corrects Alex's 28th tech TM on bytes: probes-bridge-v1.json EXISTS at the workspace root (71905533…, 44,773 B, 41 probes / 44 elements, 22 TRACED / 22 NOT_YET, four-round-reviewed 2026-07-26 with seven author keys corrected by two other seats) — the lane is resumption, not authoring; Seam 1 was never opened. Extends UCCA-BUILD-BRIEF-HARD-TRUE-POSITIVES-2026-07-26 (RULED v0.3, stands in full). The v1.2 collision stated precisely: TRACED asserts a verbatim anchor on the claim's declared basis, but no basis field ships today (A30; v2 measure-first-gated), so a bridge -pos admits two honest readings of an engine NOT_YET. RULED 2026-07-28 by Tim — all four §0 as recommended. 0.1 responsiveness-in-fact — keys stand as authored; the pre-registration commits both readings of a -pos NOT_YET before any record exists, so no verdict can post-hoc pick the flattering one. 0.2 re-run the key review under v1.2 — and the fixture's rule-credit keying convention is ENDORSED into the record by this ruling (register, not canon), so the 44 keys stop resting on an unratified author-note. 0.3 both models, mirrored (GLM-5.2 baseline + nemotron mirror) per the per-model calibration law. 0.4 rider first — Seam R. Bytes carry status: DRAFT v0.1; rulings live in this row (switcher pattern). Class B mints on run proof, never on the draft. Verifies to 2e903c49…, 93 lines. ✎ EXECUTED through Seam 5, 2026-07-28 — Seam R ae7254f (deploy 12f4a503) · Seams 1–4 engine fc89bdf12f2495d1909c220e5576 · container v34, image ffc439d7…, rollout fd3d5d59 completed · KV catalogue republished, 10 entries = registry. Pre-registration and Seam 6 NOT done — nothing fired. ground/UCCA-RESUME-BRIEF-BRIDGE-SUITE-2026-07-28.md
UCCA-SEAM-0R-REPORT-BRIDGE-SUITE-2026-07-28 Seam 0-R report — the key re-review under v1.2. Zero keys changed; three defects filed: a byte-identical duplicate probe (ops-nearmiss-visitor-escort = ops-infer-visitor-escort-neg, double-weighting one item in every rate), the endorsed rule-credit convention not carried into any of the 22 NOT_YET rationales, and a rationale describing material other than its own. Basis vocabulary clean (10 labels, all inside the closed eleven), as-built reconciled exactly, contract expressibility confirmed (anchors plural). filed ✓ (Ground) — all three defects RULED and fixed 2026-07-28 (drop · back-fill · rewrite). Verifies to f3948621…. ground/UCCA-SEAM-0R-REPORT-BRIDGE-SUITE-2026-07-28.md
UCCA-DELTA-BRIDGE-V1-REVISION-2026-07-28 Delta note — the bridge-v1 revision under the three 0-R rulings. 18 rationale edits, one probe dropped, note amended, zero expected values changed. Carries the full 22-element SCOPE/TIMING/PROXY classification, four flagged boundary calls, and the ruling sought on a fourth route — CONTRADICTION, forced by the corpus's own exit-nokey probe: "exactly three ways" was falsified by the bytes it governs. filed ✓ (Ground) — CONTRADICTION ENDORSED by Tim 2026-07-28, then bounded the same day on Alex's filed disagreement: entailment strictly — the negation must follow from the rule's own predicate; an implied-gap cadence is TIMING (emergency-lighting TIMING upheld). Canonical fixture 47d1a386…. Verifies to b2115130…. ground/UCCA-DELTA-BRIDGE-V1-REVISION-2026-07-28.md
UCCA-SEAM-REPORT-BRIDGE-R-THROUGH-5-2026-07-28 Seam report — R and 1–5 executed. The already_running rider shipped (both trigger routes now 409 instead of printing a silent refusal as triggered — the burst incident's actual defect); the delta review with one disagreement filed and ruled against, recorded as such; bridge-v1 registered class 2 / sme_validated: false, 40 probes / 43 elements pinned; expected_basis enforced conditionally per set (partial presence now fails loud); both acceptance tests shipped, with the non-collinearity test demonstrated to fire on every existing corpus and on none of bridge-v1. 102 checks green. Landmine found: the KV catalogue republish is a CI step, not part of wrangler deploy — a local deploy leaves the console dropdown lying about what is deployed. filed ✓ (Ground) — execution record for Claude's verdict. Nothing fired; pre-registration and Seam 6 outstanding. ground/UCCA-SEAM-REPORT-BRIDGE-R-THROUGH-5-2026-07-28.md
UCCA-TM-2026-07-30-C Session-close baton for 2026-07-30 UTC (C) — CURRENT SESSION REFERENCE, read first at cold start. The window that found its hardest open question had been closed six days earlier. ADR-0014, ruled by Tim 2026-07-24 and ratified into NORTHSTAR-01 §6 v1.1, already decides the strictness fork in favour of horn 2strictness is a client-set adapter policy, the throat stays blind — already states the engine's strictness-blindness verbatim in its Context, and already names the ops-nearmiss-fire-exits object as a declared inference. The capture filed earlier the same day presents all three as new. Root cause, mechanical: the ground doc's ADR list names 0001/0002/0003/0004/0006 while the log runs 0001–0015 gap-free, and five of the missing ten bear on the question. Owed rulings drop five to three. EXIT CONDITION (d) ANSWERED ON CORPUS BYTES AND RULED CLEAR BY TIM: all eleven expected_basis labels land on the three axes §6 already declares, and bridge-v1 — the first corpus able to construct a non-verbatim TRACED, sixteen of them — produced no twelfth label, breaking the 27/0/0 collinearity that made the widening matrix blind on half the answer key. (c) NOT accepted at five of seven; runs ORDERED, and the design corrected two to FOUR because the standing v1/v2 baselines are container v28 and the container has moved. The two suites never seen by a second architecture are exactly the two the default run path selects. Also: the read-only discipline on the Claude seat lifted by Tim; the single-baton invariant broken at 2e2d697 and repaired at c8c236c7; and two card defects in two cards, both caught by Alex flagging rather than assuming. SUPERSEDED 2026-07-31 by UCCA-TM-2026-07-31 — no longer the current session baton; read UCCA-TM-2026-07-31 first. Bytes untouched, still verify to 775514207d94…. ✎ Its §7 queue is DISCHARGED THROUGH ITEM 3 and re-sequenced: item 1 (step zero + filing) executed; item 2 (the trigger card) is no longer blocked — its live-container pre-flight is discharged, container v34, verified from the Claude seat; item 3 (the four bridge-v1 per_element arrays) EXECUTED AND VERDICTED at UCCA-VERDICT-BRIDGE-PER-ELEMENT-2026-07-31. Items 4–10 carry into UCCA-TM-2026-07-31 §7. Its §8 access lines are superseded — the Claude seat now reads Cloudflare directly. · Filed 2026-07-30 as the then-current session baton. Supersedes UCCA-TM-2026-07-30-B. Three commits this window: 2e2d697 · c8c236c7 · 4c13696. First baton written to disk with its digest published before its authoring session ended, per its own §6 — verifies to 775514207d94…, 121 lines, 18,912 B, and that seal existed before this relay. Its §7 item 2 carries a BLOCKING pre-flight: the four ordered runs need a live container read, because the four-runs design rests on v34 carried from a baton and re-read by nobody. Its §7 item 3 names the highest-value unread artefact in the house — the four sealed bridge-v1 per_element arrays, the first-ever measurement of the under-claim direction, already paid for. Reconfirm ALL live state via Alex — do NOT assert live from this baton. ground/UCCA-TM-2026-07-30-C.md
UCCA-TM-2026-07-30-B Session-close baton for Thu 30 Jul 2026 (B) — CURRENT SESSION REFERENCE, read first at cold start. The window that nearly spent a licensed review on the wrong question. The two four-for-four probes are NOT one finding. ops-nearmiss-fire-exits is an ill-posed item — the fixture's own note instructs rule-credit, the key applies something narrower (storedobstruction), and the engine is obeying the note; two architectures agreeing four-for-four is therefore the expected result, not a shared blind spot. ops-scope-incident-locations-neg survives as a live over-claim — there the convention is declared and the engine went the other way regardless. THE WITHDRAWAL THAT DID NOT TRAVEL: rule-credit was withdrawn as circular for state obligations by a blind commission on 2026-07-26, the fixture was never re-authored to carry obligation levels, and the 07-28 resume brief put the convention to Tim as "currently an unratified author-note" without mentioning the withdrawal — Claude authored that brief, and the omission is the root cause of both disputed keys. THE HARDEST FINDING, verified in engine code at 1fcae5c: strictness_key sits in the registry, on the fixture, in the loader and in every sealed record, and is deliberately never passed to the reasoner"never an engine behaviour (ADR-0002 — the throat stays neutral)". The keys were authored at strict-literal and the engine was asked a bare question. Not a blind spot — an unasked question, and the fork it opens (pass strictness, or re-author the keys at the engine's actual strictness) is ruling 4 of five owed. The instrument: an answer graded against an underspecified question is not a wrong answer, it is an ungradeable item, and the regress is bounded by a stopping rule requiring nobody to be right. Also: two filings executed (surfaces 8ef04b7e, docs c491caf); the stale index.lock defect traced to the Claude seat via the device bridge holding 37,289 descriptors; and four Claude over-reads ledgered by name. SUPERSEDED 2026-07-30 UTC by UCCA-TM-2026-07-30-C — no longer the current session baton; read UCCA-TM-2026-07-30-C first. Bytes untouched, still verify to 4454738452…. ✎ Its §8 queue is DISCHARGED THROUGH ITEM 3 and re-sequenced: item 1 (step zero + filing) executed at 2e2d697, with the single-baton defect it introduced repaired at c8c236c7; item 2 (the capture relay) executed at 2e2d697; item 3 is reduced from five owed rulings to three — the strictness fork is withdrawn as already-ruled by ADR-0014 (2026-07-24) and verdict grammar is restated as gated, not unruled. Items 4–8 carry into UCCA-TM-2026-07-30-C §7. Its §6 CORRECTION on the read-only mount is itself superseded — Tim lifted that discipline 2026-07-30 and this seat now writes staged documents to the workspace root directly. · Filed 2026-07-30 as the then-current session baton. Supersedes UCCA-TM-2026-07-30. Its §8 items 1 and 2 were discharged by this filing under UCCA-FILING-BRIEF-BATON-AND-CAPTURE-2026-07-30; the step-zero byte-verification of c491caf was executed at that card's §1 and matched on every leg. RECONSTITUTED ARTEFACT — read this before citing its seal: this baton was authored in a session that ended before it was ever written to disk, so it had no canonical byte form until 2026-07-30T10:00Z. The bytes filed here were re-authored from the surviving copy and verify to 4454738452…, 118 lines, 21,772 B — a seal ESTABLISHED by this filing, not checked against a prior one. No earlier seal for this doc_id exists or ever existed. Reconfirm ALL live state via Alex — do NOT assert live from this baton. ground/UCCA-TM-2026-07-30-B.md
UCCA-VERDICT-BRIDGE-PER-ELEMENT-2026-07-31 Verdict — the four sealed bridge-v1 records read DIRECTLY FROM R2 by the Claude seat, and the UNDER-CLAIM DIRECTION MEASURED FOR THE FIRST TIME ANYWHERE. Across four runs and 64 opportunities on non-verbatim true positives there was exactly ONE under-claim (ops-partial-records-secure-retain-pos, nemotron run 1, basis partial) and it did not reproduce. The false-negative cell UCCA-NOTE-BASIS-AXIS-COLLINEARITY-2026-07-26 §5 called unconstructable is now measured four times. THE FOUR-FOR-FOUR FACT IS CLAUDE-VERIFIED, no longer Alex-attestedops-scope-incident-locations-neg and ops-nearmiss-fire-exits wrong in all four runs of both architectures and nothing else is, so UCCA-CAPTURE-GRADEABILITY-AND-CONVERGENCE-2026-07-30's split stands on verified ground. GLM is element-for-element deterministic across both runs with only cost_usd moving — which itself proves the path re-inferred rather than replayed. NEW: GLM over-claims ops-nearmiss-firstaid-current in both runs where nemotron is right in both — the architectures do not fail in the same places. §4 falsifies UCCA-TM-2026-07-30-TECH §4/§7 for the Claude seat: R2 object listing over REST works, so 43 calibration records (the console figure, now verified) and exactly 2 failure markers — the "no third exists" that §7 called unproven and unprovable. §5 is the number that did not reconcile and was chased rather than reported past: nemotron run 1 shows 3 state errors against a sealed 39/43, because a fence-failed TRACED counts as incorrect — so accuracy_rate blends state correctness with anchor integrity, and anyone deriving an error count from it alone is wrong whenever fabricated_anchor_rate is non-zero. ISSUED 2026-07-31 — CLAUDE-VERIFIED END TO END, every call method: GET, no write of any kind issued. The fixture was re-hashed to 47d1a386… and the parse asserted against that digest in code before use, so the ruler is the registered ruler. All four records retrieved by exact key and reconciled against their own sealed scalars. LIFTS NOTHING: the UCCA-VERDICT-BASIS-CORRELATION-2026-07-26 §3 quarantine is untouched, no statistic is computed and none may be, and every figure remains agreement with an unsigned keybridge-v1 is class 2, sme_validated: false, its keys the contested judgement itself. Does not close ADR-0014 exit condition (c). Does not amend TECH, whose limits remain true of Alex's seat. Enumeration honesty: 177 objects for per_page: 1000 with no continuation cursor — strong evidence, not proof, and written that way.§5 CONFIRMED ON ALEX'S OWN READ 2026-07-31reasoner/calibration/__init__.py:240 reads ok = emitted_traced and ref not in broken_refs, and nemotron run 1 recomputes to 2 over + 1 under (3 state errors) + 1 fence-failed TRACED (ops-mixed-chemical-label-store) = 4 incorrect = the sealed 39/43. No disagreement to file. ground/UCCA-VERDICT-BRIDGE-PER-ELEMENT-2026-07-31.md
UCCA-CORRECTION-CF-ACCESS-SCOPE-2026-07-31 Correction by record — UCCA-RULING-RECORD-CLAUDE-CF-READ-2026-07-31 understates its own scope on four counts and misstates the write guarantee on a fifth. It says R2, D1, KV and containers "stay Alex's exclusively"all four are reachable, verified within twenty minutes of that filing through a second connector (ucca-e5a98302-api, Cloudflare's full API server): 5 R2 buckets with objects enumerated, 5 D1 databases, 5 KV namespaces, and the container at v34 / image ffc439d7… — which DISCHARGES the blocking pre-flight at UCCA-NOTE-RUN-PREREGISTRATION-DEFAULT-PATH-2026-07-30 §6 item 1, so the four-runs design holds and that item comes off the trigger card. It also says "no write tool is present in the namespace"true of claude-ucca-cf, FALSE of ucca-e5a98302-api, whose execute tool issues arbitrary GET/POST/PUT/PATCH/DELETE and whose own example PUTs a Worker script. The restraint is a read-only OAuth grant held server-side, not the tool surface — a materially weaker guarantee, and the difference is now visible rather than assumed. STANDING: this seat passes method: "GET" and nothing else, ever. THE DEFECT IS CLAUDE'S — the ruling was drafted and relayed before the second connector was tested, the same shape as the six over-reads its own §3 records, and the check was twenty minutes away. ISSUED 2026-07-31. The corrected document's RULINGS STAND UNCHANGED — rule #1 not weakened in any part, f95d4537 still absolutely prohibited, all writes still Alex's exclusively, the "via Alex only" amendment holds and is now more true than written, and the non-retroactivity of prior batons' ALEX-ATTESTED lines is untouched. Only scope and the write guarantee are corrected. Bytes untouched, still verifying to 9f73dfee…. FLAGGED, NOT ACTED ON: r2://ucca-backups carries an rtopacks/ prefix, 15 objects — prefix name listed, nothing under it opened, and nothing will be (the FI-05 discipline). With CLOUDFLARE_ZONE_RTOPACKS in the credential store and an RTOpacks-named Tunnel token in the UCCA account, that is three independent traces of the other house inside this one's infrastructure — not a breach, not asserted as one, recorded because a fence is only as good as the ledger of where it leaks. ground/UCCA-CORRECTION-CF-ACCESS-SCOPE-2026-07-31.md
UCCA-TM-2026-07-31 Session-close baton for 2026-07-31 UTC — CURRENT SESSION REFERENCE, read first at cold start. The day the drafting layer stopped being blind. RTOpacks sent an unprompted request for the engine's current runnable state — which is UCCA's own roadmap Window 3, ruled 2026-07-28 before the request existed and without either house seeing the other's plan. UCCA's reply is filed and awaiting carry as one parcel with the 24-day-old RPL answer; FI-06 banks Tim's override for a third concurrent crossing. THE ACCESS POSITION CHANGED TWICE: the API-token-from-disk route was tested and is structurally dead (sandbox egress 403s every Cloudflare host against pypi.org 200; the device VM has no network stack), and two custom MCP connectors succeeded instead, both bound to e5a98302 and verified on returned content. AND THEN THE MEASUREMENT: the four sealed bridge-v1 records read directly from R2, the under-claim direction measured for the first time anywhere — one under-claim in 64 opportunities, not reproduced — the four-for-four fact Claude-verified, and R2 enumeration falsifying TECH §4/§7 for this seat. The blocking pre-flight is discharged: container v34. Three cards, three commits, and the first card all day that Alex reported with nothing to flag — because it was the first to carry an explicit false branch. SUPERSEDED 2026-07-31 by UCCA-TM-2026-07-31-B — no longer the current session baton; read UCCA-TM-2026-07-31-B first. Bytes untouched, still verify to 03033343c029…. ✎ Its §7 queue is DISCHARGED THROUGH ITEMS 1 AND 3 and re-sequenced: item 1 (step zero) executed at c0bd71b; item 3 (the runnable-state recon) BRIEFED, APPROVED AND HALF-EXECUTED — Lane A at UCCA-RECON-LANE-A-FINDINGS-2026-07-31, Lane B not yet relayed. Item 2, THE CARRY, is untouched and remains the oldest thing owed. Items 4–10 carry into UCCA-TM-2026-07-31-B §6. · Filed 2026-07-31 as the then-current session baton. Supersedes UCCA-TM-2026-07-30-C. Three commits this window: 82c06f9 · 4da4c23 · 277412e. Written to disk with its digest published before the session endedverifies to 03033343c029…, 121 lines, 15,110 B. Its §7 item 2 is the oldest thing owed in the house: the parcel in canon/sent/ is filed, unblocked, and still uncarriedUCCA-CROSSING-RPL-CAPABILITY-ANSWER-01 since 2026-07-06. Its §9 records three traces of RTOpacks material resident inside UCCA infrastructure, flagged and not acted on, and puts to Tim whether resident other-house material warrants a standing fence-log entry as distinct from material that crosses. Reconfirm live state — but note that reconfirmation is now available to both seats, which is the day's structural change. ground/UCCA-TM-2026-07-31.md
UCCA-RESUME-CARD-CLOSE-2026-07-31 Resume card — the filing card that halted at its own §6 was resumed rather than reissued, and the halt was CORRECT. UCCA Alex refused to reconstruct three load-bearing anchors from a prose summary when the card itself was absent from disk, and on §2 that refusal was decisive: one occurrence of CURRENT SESSION BATON on line 59 had to deliberately SURVIVE, so a near-miss anchor would not have failed loudly — it would have silently destroyed the live marker. Rules option 1 on the baton-marker defect: the phrase belongs in the status slot only, CURRENT SESSION REFERENCE in the description slot, and both rows are normalised. Adds a third replacement Alex's own proposal did not have — his scorer/__init__.py:240 citation names a path that does not exist anywhere on the mount; line number and expression are exact, the file is reasoner/calibration/__init__.py, and it was caught while still staged rather than after reaching canon. EXECUTED 2026-07-31 at c0bd71b. Every gate tested, every gate passed, no false branch fired — two rms, the four-path status check, three anchor-uniqueness checks, four counts, no duplicate rows, commit and push first time. §3 measured what grep -c could not see: 2 matching LINES but 3 OCCURRENCES, line 59 carrying the phrase in description and status — the single-baton invariant had been blind since the phrase first appeared twice on one row. Counter hardening deliberately DEFERRED to its own ruling rather than ridden through inside a filing commit. Its §0 records Claude's defect: two index.lock files left by a git status the device mount cannot unlink. ✎ COUNTER HARDENING RULED 2026-07-31 by Tim — option 4, the BARE-OCCURRENCE rule (see UCCA-RESUME-CARD-COUNTER-2026-07-31 §0): the single-baton invariant counts only occurrences not wrapped in backticks, so a marker asserted in prose counts and a marker cited as a string does not. The deferral recorded above is DISCHARGED, not outstanding. The rule re-baselines nothing — all 36 occurrences of the three phrases in this register already obey it, 34 bare markers and 2 backticked citations, no exception — and it is precisely why this row's own description may cite CURRENT SESSION BATON and CURRENT SESSION REFERENCE verbatim without breaking the check. Alex's option 3 is recorded as REJECTED ON MECHANISM, not on preference: cell-scoping fixes the baton phrase and cannot fix CURRENT SESSION REFERENCE, whose seventeen live markers and one citation share the description cell. The four counts become three — the line-count and occurrence-count variants of the baton check collapse into one. ground/UCCA-RESUME-CARD-CLOSE-2026-07-31.md
UCCA-RECON-BRIEF-RUNNABLE-STATE-2026-07-31 Recon brief — the live-read pass UCCA-CROSSING-ENGINE-STATE-RESPONSE-01 §2 promised RTOpacks before the runnable-state document is written. Splits their eight numbered asks across two seats by what each can actually reach: the Claude seat answers where output lands and produces the verbatim example artefact over GET; UCCA Alex answers everything living in D1 — what has been run, on what, when, how long, at what cost. CARRIES TIM'S TWO RULINGS OF 2026-07-31 VERBATIM AT ITS §0, and they are canon nowhere else — search §0 in this document for both. RULING 1: the GET-only rule is VERB-BOUND — D1's read endpoint is a POST and is therefore closed to the Claude seat notwithstanding that a SELECT mutates nothing, because the rule's value is that it is mechanically checkable and a semantics-bound rule is judged per request by the same seat making the request. RULING 2: the parcel carries AS-IS — the crossing's §2 claim that this house "cannot enumerate object storage" was true when authored and false twenty hours later; not repaired, not amended, no addendum, carry not delayed. Its §3 states the constraint that could have sunk ask 2: the example output crosses the fence, so it must be engine-side material or it cannot be used at all — and if the only genuine runs are over client-domain material, ask 2 is reported unanswerable rather than answered with a fixture dressed as a run. APPROVED by Tim 2026-07-31; Lane A EXECUTED (see UCCA-RECON-LANE-A-FINDINGS-2026-07-31); LANE B NOT YET RELAYED. Nothing in it runs the engine — brief §5 requires that any ask needing a run be answered "not established without a run" and the run proposed separately for Tim's approval. The runnable-state document is NOT started and may not be, per §7: writing it from one lane and backfilling the other is the exact fossil RTOpacks' §17 asked this house not to send. Lane B's first question has since changed — it is now the seventeen silently-incomplete runs, not ask 1. ground/UCCA-RECON-BRIEF-RUNNABLE-STATE-2026-07-31.md
UCCA-RECON-LANE-A-FINDINGS-2026-07-31 Lane A findings — the Claude-seat half of the recon, every call method: GET, and it found more than it was sent for. ASK 7 ANSWERED: one bucket holds engine output — ucca-artefacts, 177 objects: 69 payloads · 45 calibration · 40 envelopes · 12 diagnostics · 5 authz · 3 reverify · 2 costprobes · 1 revocations. ASK 2 IS ELIGIBLE: the envelope's obligation_ref is a public unit code and the material traced against it is UCCA-authored synthetic prose — no client material, it crosses. AND THE ARTEFACT CARRIES A FIELD THIS HOUSE DID NOT KNOW WAS THERE — "attests": "provenance-only". The seal declares IN THE ARTEFACT that the signature attests provenance and NOT the correctness of the findings: FOUNDATION-01 §2 is not a policy written about the engine, IT IS A FIELD IN THE OUTPUT — and the chosen envelope was subsequently REVOKED, making response §70 on renderings outliving claims concrete rather than theoretical. THE FINDING NOBODY ASKED FOR, computed in code and never counted by eye: 69 payloads → 40 envelopes → ZERO orphans, but 29 runs produced no envelope and SEVENTEEN produced no failure marker either. A quarter of everything ever submitted ended in neither a credential nor a recorded failure. ISSUED 2026-07-31 — CLAUDE-VERIFIED, every call method: GET, no write of any kind and no D1 query. The honest limit is stated and is load-bearing: absence in R2 is NOT proof of an absent D1 row. Whether the seventeen have sealed rows is Lane B's first question, and it goes one of two ways that both matter — either R2 and D1 disagree about what happened and nobody documented it, or the job-rows-are-permanent rule has a hole seventeen runs wide. ucca-backups was NOT OPENED AT ALL this pass — not listed, not sampled, not counted; the fence discipline costs one line of the answer and is worth more than the line. Logged and NOT resolved: the only real runs on record are VET-shaped — a fact about the evidence, not about the engine, and obligation_ref is an opaque string. Enumeration honesty: 177 objects at per_page: 1000 with no continuation cursor — strong evidence, not proof, and written that way. ground/UCCA-RECON-LANE-A-FINDINGS-2026-07-31.md
UCCA-TM-2026-07-31-B Session-close baton for 2026-07-31 UTC (B) — CURRENT SESSION REFERENCE, read first at cold start. The day the engine's own output answered the question the canon had been arguing about all week. Step zero closed clean at c0bd71b — counts 1 · 1 · 15 · 16, every gate tested, no false branch fired. Tim ruled twice (verb-bound GET; carry as-is), both recorded at UCCA-RECON-BRIEF-RUNNABLE-STATE-2026-07-31 §0. Lane A ran and found attests: provenance-only in a sealed envelope — and seventeen runs that produced no credential and no failure record. Its §4 founds the rule Claude broke the same day: an artefact intended for UCCA Alex is not delivered until it is written to the device and its digest verified THERE — delivery into Tim's conversation is delivery to Tim, not to the substrate. Also founded: git status from the Claude seat uses --no-optional-locks; the workspace has SIX git repos, not five, trust/ucca-trust having been absent from Alex's lock sweep all session; and grep -c counts LINES, not occurrences. SUPERSEDED 2026-07-31 by UCCA-TM-2026-07-31-C — no longer the current session baton; read UCCA-TM-2026-07-31-C first. Bytes untouched, still verify to f69524329be7….ITS TITLE AND §3 ARE FALSIFIED on the seventeen silently-incomplete runs — there are fourteen, all sealed with named dispositions, and the ledger has no hole; corrected by record at UCCA-CORRECTION-SILENT-RUNS-2026-07-31, bytes untouched. Its §6 queue is DISCHARGED THROUGH ITEMS 1, 3 AND 5 — step zero executed at 2b60dc95; Lane B relayed, executed and verdicted; the counter hardened by ruling. Item 2, THE CARRY, is untouched and remains the oldest thing owed. Items 4–10 carry into UCCA-TM-2026-07-31-C §10. · Filed 2026-07-31 as the then-current session baton. Supersedes UCCA-TM-2026-07-31. Written to disk and verified on the device before its digest was published — verifies to f69524329be7…, 107 lines, 13,590 B. Its §5 predicted its filing card's counts and was RIGHT while the instrument was WRONG, which is what produced ruling 3. Reconfirm ALL live state via Alex — do NOT assert live from this baton. Supersedes UCCA-TM-2026-07-31. Written to disk and VERIFIED ON THE DEVICE before its digest was published at all — the sharper form of the UCCA-TM-2026-07-30-C §6 rule. Verifies to f69524329be7…, 107 lines, 13,590 B. Its §5 predicted this filing card's counts before the card existedthen-current 15 → 16 and REFERENCE 16 → 17, with BATON unchanged at 1 because one marker goes out as one comes in. Its §6 item 2 remains the oldest thing owed in the house: the parcel in canon/sent/ is filed, unblocked, and still uncarried — UCCA-CROSSING-RPL-CAPABILITY-ANSWER-01 since 2026-07-06, now 25 days. ground/UCCA-TM-2026-07-31-B.md
UCCA-RULING-RECORD-2026-07-31 Ruling record — Tim's four rulings of 2026-07-31, none of which had a canon home before this document, closing UCCA-TM-2026-07-31-B §6 item 1. (1) The GET-only rule is VERB-BOUND — D1's read endpoint is a POST and is closed to the Claude seat however read-only a SELECT is, because a semantics-bound rule is judged per request by the seat making it. (2) The parcel carries AS-IS — a capability clause true when authored and false twenty hours later is not repaired, amended or delayed; filed artefacts are historical. (3) The single-baton invariant counts BARE OCCURRENCES ONLY — option 2 rejected as adjusting text to satisfy a check, option 3 rejected ON MECHANISM: cell-scoping cannot fix CURRENT SESSION REFERENCE, whose seventeen markers and one citation share a cell. All 36 occurrences checked in code: 34 bare markers, 2 backticked citations, zero exceptions — the rule was already universal and unwritten. (4) Never backdate; read before rewrite. FILED 2026-07-31. Records; rules nothing new. Ruling 4 is recorded WITH THE FALSE PREMISE IT WAS FIRST PUT ON — Claude sought "fix forward" against a code path that does not exist, and two of its three legs were void when put: fix forward retracted, reconciliation record already existed as fossil-ledger L8 since 2026-07-05, never backdate stands. Ruling 4(b) is what stopped a corrected number being attached to a still-false story. Verifies to 405d26e12299…, 83 lines, 9,243 B. ground/UCCA-RULING-RECORD-2026-07-31.md
UCCA-TM-2026-07-31-C Session-close baton for 2026-07-31 UTC (C) — CURRENT SESSION REFERENCE, read first at cold start. The day the house's most alarming finding turned out to be three errors stacked on a canon row filed three weeks earlier. THE SEVENTEEN DO NOT EXIST — there are fourteen, every one a sealed D1 row with a named disposition; R2 and D1 reconcile exactly; the job-rows-are-permanent rule holds without exception. Three were completed reverify jobs, listed at 3 objects in Lane A's own §1 inventory, one table above the §2 arithmetic that ignored them. THE MECHANISM WAS CLAUDE'S AND IT WAS FALSE — the two failure codes live in six .md files and zero code files, hand-applied during the 3–4 July remediation, and the claim was relayed to Alex one grep short of being checked. AND CANON HAD IT ON 2026-07-05fossil-ledger L8, disposition no work owed. THE ONE NEW THING IS THE DRIFT: 26 not 25, and the extra is e61b41fa, 2026-07-21, client_id = rtopacks — the engine's only live-era failure was on the client's own work. FILED 2026-07-31 — SUPERSEDED 2026-07-31 by UCCA-TM-2026-07-31-D — no longer the current session baton; read UCCA-TM-2026-08-01-H first. Bytes untouched, still verify to 675dc2535dd3…. Supersedes UCCA-TM-2026-07-31-B. Written to disk and verified on the device before its digest was published at all. Verifies to 675dc2535dd3…, 126 lines, 16,929 B. Three commits this window: 2b60dc95 · a9a8e2d · this one. Nothing carried — the parcel is 25 days uncarried and ruling 2 removed the last blocker without moving it. AN RTOPACKS REPLY IS IN TIM'S HANDS AND DELIBERATELY UNREAD, held so the correction was drafted from this house's substrate rather than around the other house's words; it opens the next window, and whether anything has actually crossed must be asserted from the fence log first. Its §10 carries eleven open items; the runnable-state document is unblocked for the first time, both lanes having reported. Reconfirm ALL live state — do NOT assert live from this baton. ground/UCCA-TM-2026-07-31-C.md
UCCA-CORRECTION-SILENT-RUNS-2026-07-31 Correction by record — the seventeen silently-incomplete runs do not exist, and neither does the mechanism this house invented to explain them. There are FOURTEEN; every one carries a sealed D1 row with a named disposition; R2 and D1 reconcile exactly; and the job-rows-are-permanent rule holds without exception. Three of the seventeen were completed reverify jobs writing to default/reverify/ — a prefix Lane A's own §1 inventory lists at 3 objects, one table above the §2 arithmetic that ignored it. THE MECHANISM CLAIM IS FALSE AND IT WAS CLAUDE'S: QUEUE_WEDGE_CONTENTION and QUEUE_PURGED_CONSUMER_WEDGE appear in six files, all .md, and zero code files — applied by hand during the 3–4 July remediation (INPUT-PATH-BUILD.md:260), so the "queue-layer failures never write diagnostics" code path does not exist; the automated sweeper that replaced it does write its diagnostic (consumer-shim.js:226, :264). AND CANON HAD ALL OF IT ON 2026-07-05: fossil-ledger L8 filed the exact decomposition — 11+6+5+3=25, era-bounded, ADR-0006 cure, "not live production failures"three weeks and two days before this house re-derived it as a discovery. FILED 2026-07-31. Corrects three filed documents without amending any bytes: UCCA-RECON-LANE-A-FINDINGS-2026-07-31 on three counts (the 7+5 diagnostics split, the undeclared eight-of-seventeen truncation, and the reverify miss that falsifies its §2 headline), UCCA-TM-2026-07-31-B's title on one, and Claude's own session verdict on one — the worst of the four, and relayed to Alex before it was checked. WHAT STANDS UNQUALIFIED: Lane A's set arithmetic reproduces exactly on an independent listing; zero orphan envelopes; the attests: provenance-only finding untouched; ask 2's fence eligibility untouched and not reopened, having rested on the envelope's own content and never on material_source. Lane A stated the limit that saved itabsence in R2 is not proof of an absent D1 row — which is why this cost one read rather than a retraction across the fence. FLAGS A DRIFT IT DOES NOT FIX: L8 records 25 failures, the live read 26, and L8's "live-era rate currently 0" is stale. Proposes one standing rule, unruled: canon and the fossil ledger are searched for a number before any live read is promoted to a finding. Verifies to fb82125067a9…, 105 lines, 13,224 B. ground/UCCA-CORRECTION-SILENT-RUNS-2026-07-31.md
UCCA-RULING-RECORD-CLAUDE-CF-READ-2026-07-31 Tim's ruling, 2026-07-31 — the Claude seat gains DIRECT READ access to UCCA Cloudflare state for the first time in this house's history, through a purpose-built custom connector (claude-ucca-cf) authorised by Tim against e5a98302. RULE #1 IS NOT WEAKENED IN ANY PART: f95d4537 remains absolutely prohibited, the RTOpacks-bound mcp__Cloudflare_Developer_Platform__* connector remains never-used with no reads and no writes, and all Cloudflare writes remain UCCA Alex's exclusively — the Claude seat holds no write capability and must never acquire one. What is amended is the single adjacent sentence "all UCCA Cloudflare state via UCCA Alex only", which is now false. NOT RETROACTIVE — every ALEX-ATTESTED, NOT CLAUDE-VERIFIED line in every prior baton stands as written. CAN reach: Workers list, Worker config, deployed Worker source (so deployed vs committed is now checkable — a class of verification neither seat could perform before), and Workers observability logs/metrics. CANNOT reach, and these stay Alex's exclusively: R2 (so the four sealed bridge-v1 records and every UCCO envelope), D1, KV, container version and image, and the Access-gated Control Rail. The trap named before it is fallen into: partial access invites "not in what I can see, therefore not there"absence is now unprovable from this seat for two reasons rather than one, and a read this connector cannot make is a question for Alex, never a negative result. STANDING GUARD: the connector name carries no account ID and a connector can be re-authorised without its name changing, so a session verifies the binding on returned content before relying on it — workers_list must return UCCA-shaped names and zero RTOpacks-shaped names, and any RTOpacks-shaped resource is a full stop and a flag (the FI-05 discipline). FILED 2026-07-31. Identity verified live at ruling time on returned content, not on the connector's label: 22 Workers, every name UCCA-shaped or a known UCCA-side proxy, zero RTOpacks-shaped, with ucca-reasoner modified_on 2026-07-28T01:36:46Z and ucca-admin-api 2026-07-28T00:53:32Z independently corroborating engine HEAD 1fcae5c. Capability surface enumerated from the connector's own tool list — eight tools, every one read, no write tool present in the namespace. NEGATIVE RESULT FILED SO IT IS NOT RE-ATTEMPTED: the API-token-from-disk route is structurally dead — the cloud sandbox's egress proxy returns CONNECT tunnel failed, 403 for every Cloudflare and *.ucca.online host while pypi.org returns 200, and the device VM has no network stack at all; the staged credential copy was deleted from the container. ALSO RECORDED: .credentials/cloudflare.env is not a Cloudflare file — it holds 26 variables including VC_SIGNING_PRIVATE_JWK, the UCCO signing key — and must never be staged anywhere; two defects in it flagged and not repaired (AUTH0_AUDIENCE defined twice, resolving silently to the last; and a variable named KEY_SERVER_SECRET_UNRESOLVED_FROM_MEMORY_2026_04). AND ONE GAP SURFACED IMMEDIATELY: the account holds 22 Workers where the substrate tables describe roughly six — ucca-transcript-signer, ucca-authz and ucca-status-reader were created 22–23 July and appear in no substrate table. Nothing asserted wrong; noted because the substrate beats any summary of it. · §3 SCOPE AND WRITE-GUARANTEE STATEMENTS CORRECTED BY RECORD 2026-07-31 — see UCCA-CORRECTION-CF-ACCESS-SCOPE-2026-07-31. R2, D1, KV and containers are reachable, not exclusive to Alex; and "no write tool is present in the namespace" is false of ucca-e5a98302-api, whose execute tool is fully write-capable and restrained only by a server-side read-only grant. The rulings stand unchanged — rule #1 not weakened, writes still Alex's exclusively. Bytes untouched, still verify to 9f73dfee…. ground/UCCA-RULING-RECORD-CLAUDE-CF-READ-2026-07-31.md
RTOP-ENGINE-STATE-REQUEST-2026-07-30 Received copy — RTOpacks asks UCCA for a filed statement of the engine's CURRENT RUNNABLE STATE, as gate-1 input to an RTOpacks thin end-to-end thread: one qualification in, something out, landing on a viewable RTOpacks surface labelled BETA / uncalibrated, quality deliberately deferred. Eight numbered asks — input · output (with one real artefact verbatim, "warts and all") · invocation · what it has actually been run on · what breaks ("this section being long is a good sign") · timing and cost · where output lands · what it needs and doesn't have. Requests the answer as a UCCA-prefixed document in UCCA's own terms — "authorship stays home; RTOpacks will not re-prefix it" — and states plainly that nothing is committed or promised on the basis of it. NOTE THE CONVERGENCE: this describes UCCA's own roadmap Window 3, ruled 2026-07-28 before the request existed and without either house seeing the other's plan. RECEIVED AND FILED 2026-07-30 UTC — byte-verbatim, unedited, NOT promoted to home canon. Local force is home-side and is UCCA-CROSSING-ENGINE-STATE-RESPONSE-01 plus the runnable-state document it commits to. Two carriage defects, flagged and NOT repaired (respond-never-redline): it crossed without a digest9a29b475f79f71278e926c73982ea70957b76e414e8b87cd03b189efe0d95772 (42 lines, 2,844 B) was computed on receipt on the UCCA side, with no origin manifest to check it against, and if RTOpacks publishes a different digest theirs governs and this is re-filed; and it carries no YAML frontmatter where UCCA filing convention expects one. Relayed by Tim, sole relay both directions. canon/received/RTOP-ENGINE-STATE-REQUEST-2026-07-30.md
UCCA-CROSSING-ENGINE-STATE-RESPONSE-01 Crossing, UCCA-authored original of record — the answer to RTOP-ENGINE-STATE-REQUEST-2026-07-30. Accepts the runnable-state document and names the honest limit on timing: most of what was asked for is live substrate the drafting layer is structurally blind to — it cannot enumerate object storage and the operator console is unreachable to it — so the document follows a reconnaissance pass with live reads rather than being written from documentation. States that this is the request being honoured, not deferred: answering a runnable-state question from one's own docs is exactly the failure §17 of the request warns against. Names the convergence — RTOpacks' thin thread and UCCA's Window 3 are the same shape, derived independently. States the one non-negotiable constraint: the engine raises hands and never signs; TRACED asserts an anchored, responsive, byte-verified trace on a declared basis and nothing more, NOT_YET_TRACED is an honest gap and never a finding of non-compliance, and no BETA label changes either — so a surface rendering a finding as compliant/met/passed asserts something the engine did not. Carries 23 questions in three tiers: scoping (who compiles, since ADR-0002 puts the compiling adapter client-side — "if your thin thread assumes the engine ingests a qualification code and does the compiling, the thread has a component in it that neither house has built"), hard (who is the accountable human · appetite for confident wrongness given the measured over-claim direction · what if it returns almost nothing, a direction never tested anywhere · what would make you abandon it · is the real subject the engine or the seam between the houses · how much must run without Tim), and what-if (obviously vs subtly wrong · open enumerations · what if the engine disagrees with their experts · what if the bottleneck isn't the engine · what in this document reads as UCCA describing RTOpacks' house — name it and we withdraw it). FILED 2026-07-30 UTC to canon/sent/ — AWAITING TIM'S VERBATIM CARRY. Filing precedes relay; it has not crossed at filing time. Crosses in ONE PARCEL with UCCA-CROSSING-RPL-CAPABILITY-ANSWER-01 (filed to sent/ 2026-07-06, still uncarried at 2026-07-30, twenty-four days), on Tim's ruling that RPL and the thin thread are "the same parcel, just in a different wrapping." Commits UCCA to no scope, no date, no capability and no price; states no requirement for RTOpacks and authors nothing on their behalf — every item in §§4–6 is a question, and each UCCA constraint is labelled as UCCA's and sourced to filed canon. Asserts no live engine state whatsoever. Actor names qualified throughout per protocol. Verifies to 3a124d02f2f1…, 97 lines, 16,441 B. canon/sent/UCCA-CROSSING-ENGINE-STATE-RESPONSE-01.md
UCCA-RULING-BRIEF-STRICTNESS-FORK-2026-07-30 Ruling brief — THE STRICTNESS FORK WAS NOT AN OPEN RULING. Tim ruled it on 2026-07-24 as ADR-0014"every finding declares its basis; strictness is a client-set adapter policy"horn 2 of the fork, ratified into NORTHSTAR-01 §6 v1.1 and carried in this register ever since. The engine's strictness-blindness was not a discovery either: ADR-0014's own Context states it verbatim six days earlier ("the engine is strictness-blind… those are labels on the record, not inputs to the throat"), and ADR-0014 already names the ops-nearmiss-fire-exits object by shape — "a declared inference… honest in one domain and a forbidden over-reach in another." The capture's §5 sharpening that the ADR-0002 citation over-reaches is itself already minted at ADR-0015. Reduces the owed-ruling list from five to three: the strictness fork withdrawn as already-ruled; verdict grammar re-stated as ruled-in-principle, gated-in-build; level classification, the two absent failure modes, and the gradeability test stand owed. §3 owns the defect and names the mechanism: the ground doc's ADR list runs 0001 · 0002 · 0003 · 0004 · 0006 while the log runs 0001–0015 gap-free — "I worked from the list, not the log" — proposing the standing consequence that a citation to an ADR is not read until the ADR file is opened. §5 then re-frames what is actually owed as a gate check, not a ruling, and clears (a) and (b) on bytes. FILED 2026-07-30 — NOT A RULING. Puts two questions and takes neither. Corrects UCCA-CAPTURE-GRADEABILITY-AND-CONVERGENCE-2026-07-30 §5 and §10 item 4 (filed 2e2d697) without amending them — the capture's bytes stay at b40005fe… and the correction lives here, per the house rule the capture's own delivery slip states. Its §5(d) self-flags one unverified item — NORTHSTAR-01 §6's four-label vocabulary quoted second-hand from ADR-0014 because the file was not located that session; closed the same day by UCCA-NOTE-EXIT-CONDITION-D-2026-07-30, which read NORTHSTAR on its own bytes. Verifies to 44c4508c…, 124 lines, 15,331 B. ground/UCCA-RULING-BRIEF-STRICTNESS-FORK-2026-07-30.md
UCCA-NOTE-EXIT-CONDITION-D-2026-07-30 Note — ADR-0014 exit condition (d) answered on bytes: NO NEW BASIS-STATE. All eleven expected_basis labels land on the three axes NORTHSTAR-01 §6 already declares — six collapse onto the four ratified bases (verbatim · not_yet · inference with three gradations · ungrounded), and the rest sit on the scope and temporal axes §6 declares separately from basis, so none is a fifth base. Leg two is the load-bearing half: the seven widening suites could not have surfaced a new basis on the TRACED side — expected_basis: verbatim was exactly the expected: TRACED set, 27/0/0, identity in each of the seven separately — whereas bridge-v1 breaks that collinearity and still produced no twelfth label: verbatim is 6 of 22 TRACED and sixteen non-verbatim TRACED elements exist, so the cell the collinearity note called unconstructable is constructed sixteen times and the vocabulary held. FILED 2026-07-30 — NOTE, RULES NOTHING. Evidence base for both rulings at UCCA-RULING-RECORD-ADR-0014-GATE-2026-07-30. Supersedes an unfiled first issue at 39c19b1b… which asserted "the seven widening suites, GLM-5.2 only to date"false for five of the seven, falsified by Alex's record read, corrected in place before filing with the lineage recorded at its §4.1 rather than silently repaired; 39c19b1b… is not on disk and must not be filed if it surfaces. §4.1 also records this as the third time that same belief has failed, after UCCA-NOTE-RUN-PREREGISTRATION-SWITCHER-2026-07-27 §19. Reads NORTHSTAR-01 §6 on NORTHSTAR's own bytes, closing the preceding brief's §5(d). Verifies to 034750a2…, 136 lines, 17,670 B. ground/UCCA-NOTE-EXIT-CONDITION-D-2026-07-30.md
UCCA-RULING-RECORD-ADR-0014-GATE-2026-07-30 Ruling record — Tim, 2026-07-30, two rulings on ADR-0014's measure-first gate. (d) "no new basis-state surfaced by the wider matrix" CLEARS, on the evidence at UCCA-NOTE-EXIT-CONDITION-D-2026-07-30 — and clears on stronger evidence than the condition was written to require, because it now rests on a corpus that can look in both directions, which the widening matrix could not. (c) "a 2nd Workers-AI model on the same suites" NOT accepted at five of seven: Tim declined the purposive readingthe condition is met by evidence or it is not met — and ordered the outstanding runs over v1 and v2. The independent reason, which outranks the gate: LATEST_PROBE_SET_VERSION = "v2" and v1 is the regression baseline, so the two suites never seen by a second architecture are exactly the two the default run path selects — every default calibration in this house's history is single-architecture, and no filed document said so before today. RULED 2026-07-30 by Tim ("ok yes to both"), framing and evidence Claude's. THE GATE IS NOT DECLARED CLEAR: (a) and (b) were cleared before today, (d) clears here, and (c) clears when the ordered runs are sealed and read, not before — the finding-contract v2 build stays gated. Mints nothing; touches no schema, probe_set_version, corpus or key; the frozen ucca-diagnosis-findings-schema-v1.json is untouched. Fires no run — the design is pre-registered separately and files before any trigger ships. Does not lift the UCCA-VERDICT-BASIS-CORRELATION-2026-07-26 §3 quarantine, and asserts nothing about engine behaviour on the sixteen non-verbatim true positives, whose per_element arrays remain unread. Verifies to cc9e9831…, 56 lines, 8,052 B. ground/UCCA-RULING-RECORD-ADR-0014-GATE-2026-07-30.md
UCCA-NOTE-RUN-PREREGISTRATION-DEFAULT-PATH-2026-07-30 Run pre-registration — the default-path two-model pass over v1 and v2, fixed BEFORE anything fires. FOUR RUNS, NOT TWO, AND THAT IS A CORRECTION TO WHAT WAS ORDERED. The standing GLM baselines for these suites are container v28 records from 2026-07-24 and the container is now v34, so a nemotron-only pass would vary the model and six container versions at once — "any absence of difference would read as reassurance while resting on the same confound"the collinearity failure again in a different coordinate. The 2026-07-27 switcher pass avoided exactly this with matched GLM controls, and this design mirrors it: GLM and nemotron, both suites, same container, one window. Trigger list enumerated positively; fixtures pinned by digest (v1 1ba035d2… 10/11, v2 9a97e4fe… 14/15); 26 element-pairs. TWO ANALYSES DECLARED IMPOSSIBLE IN ADVANCE: neither fixture carries expected_basis on any probe (0/10 and 0/14 — absent, not empty), so no basis partition exists at any sample size and any later one is a fabricated category; and v1/v2 are the only two suites registered at strictness_key: "expert", so nothing here is cross-suite comparable on the re-mark lens. The outcome table is fixed with the null named — row A (26/26 agree) is the expected result and is pre-named so it cannot be quietly promoted into a finding; no statistic may be computed on 26 pairs. FILED 2026-07-30 — PRE-REGISTRATION. NOTHING FIRES ON IT. Ordered by ruling 2 of UCCA-RULING-RECORD-ADR-0014-GATE-2026-07-30; the trigger card ships separately and only after this is filed and pushed, per the standing rule founded when a trigger card shipped alongside its blocking filing relay and the runs beat the pre-registration into the repo by twelve and four minutes. Self-voiding clause: if any v1/v2 run lands in R2 with a measured_at earlier than this document's filing commit, the pre-registration is VOID for that run on its own terms. §6 sets three blocking pre-flight items for Alex — the live container version and image must be re-established by a real read (v34 is carried from a baton and not re-read; §1's confound argument turns on it), both fixture digests re-checked, and this filing confirmed pushed. Verifies to f370353b…, 100 lines, 13,227 B. ground/UCCA-NOTE-RUN-PREREGISTRATION-DEFAULT-PATH-2026-07-30.md
UCCA-CAPTURE-GRADEABILITY-AND-CONVERGENCE-2026-07-30 Capture — gradeability, the unasked question, and where the repair actually lives. CAPTURED, NOTHING RULED. Separates the two four-for-four probes into an ill-posed item (ops-nearmiss-fire-exits) and a live over-claim (ops-scope-incident-locations-neg), and holds them apart deliberately so the second is not flattened into the first. Re-attaches the 2026-07-26 blind-commission withdrawal of rule-credit to the registered fixture, which never carried it. Reads the 27 distinct obligation elements and finds roughly 24 of 27 are state-shaped — so the exposure is not two keys but a level-classification question standing against most of the corpus (Claude's reading of 27 texts, labelled as a reading, not a field that exists). §5 is the load-bearing section: strictness_key is verified in engine bytes at 1fcae5c as declared in four places and withheld from the reasoner on an ADR-0002 citation, and the fork — the citation over-reaches and strictness should be passed, or the citation holds and the keys must be re-authored at the engine's actual operating strictness — is stated with Claude explicitly not picking. §7 splits the repair into three layers and only the middle one is code: rulings decide semantics, code deletes the silence, and the gradeability test must NOT be automated — a panel of models makes the engine its own referee and breaches FOUNDATION-01 §2 from a new direction. §8 owns the root cause: Claude's own 07-28 resume brief omitted the withdrawal. §10 names five owed rulings and takes none, and re-aims UCCA-VERDICT-BRIDGE-RUN-2026-07-30 §9(b) from a broad SCOPE-key review to one blind questionis an unmarked enumeration in a compliance document read as exhaustive? FILED 2026-07-30 — CAPTURE CLASS, MINTS NOTHING. Rules nothing, closes nothing, authorises no build, changes no key, and does not cure the UCCA-BUILD-BRIEF-HARD-TRUE-POSITIVES-2026-07-26 §2 SME blocker. Seam 1 not reopened; no canon amended. Byte-verified: b40005fed1d5…, 184 lines, 28,025 B — matching the seal published at UCCA-TM-2026-07-30-B §7 before the filing session opened, so these are the drafted bytes and not a re-authoring. Supersedes an unfiled draft at 67c36dd5… that never left the seat and is recorded at its §9 rather than filed. Its four §5 code quotations are Claude-read against 1fcae5c (ad89ee32…, 3bbd48e7…); the four-for-four fact itself remains Alex-attested and never Claude-read, and the capture re-reads if that attestation moves. ground/UCCA-CAPTURE-GRADEABILITY-AND-CONVERGENCE-2026-07-30.md
UCCA-TM-2026-07-30-TECH Tech time machine — Alex's seat, close of the bridge-lane window. States substrate and capability; issues no verdict, rules nothing. Companion to UCCA-TM-2026-07-30, restating none of it. Carries five repo HEADs re-read by rev-parse at write time, the engine suite re-run at write time (102 PASS / 0 FAIL across 11 files — re-run, not quoted), the fixture re-hashed to 47d1a386…, and all four sealed bridge-v1 records with body digests and all four signatures re-derived and RSA-PSS-SHA256 verified against keys fetched from each record's own verification_method. §4 is the ACCESS MAP and is the reason this is filed — CAN/CANNOT stated as capability rather than as findings, because both of that window's process failures were a seat reasoning past the edge of its own access. Load-bearing: R2 enumeration is impossible from that seat (AccessDenied on ListObjectsV2, no Cloudflare REST listing endpoint), so presence is provable by exact-key GET and absence is not provable at all; admin.ucca.online returns 302 on every path; the container image is unreadable, so fixture identity in the image is inferred from header fields and must never be reported as a re-hash. §5 is the reproducible seal-verification procedure, including the trap that cost an hour: Python's json.dumps renders 0.0 where JSON.stringify renders 0, so a record carrying fabricated_anchor_rate: 0.0 canonicalises two bytes long and both the content hash and the signature fail in a way indistinguishable from a bad seal — canonicalise in actual JS. §6 carries the index.lock diagnosis with process evidence and the finding that lsof's exit code is useless in this workspace. §7 names four things that seat did not verify, and §8 carries the landmines — including the readCalibrationHistory limit: 200 truncation that fails silently, in the reassuring direction. FILED 2026-07-30 — TECHNICAL COMPANION, NOT A BATON. Authored unfiled and explicitly "rules nothing, verdicts nothing, files nothing"; filed on Tim's ruling of 2026-07-30T10:00Z because its access map, seal procedure and landmine list existed on exactly one disk, which is the same exposure class as the unfiled ~/Downloads/app/ documents at UCCA-TM-2026-07-30-B §8 item 4. Byte-verified: 182aadc925e0…, 180 lines, 12,488 B — matching the seal Alex published with it. Its §7 exclusions are binding: do not cite the R2 counts (39 → 41 → 43), the failures/ completeness claim, or the contention probe to that seat — all are Tim's console, not its own read. Its §1 tracking-state line is of-that-moment, not a live claim. · §4 and §7 ACCESS LIMITS SUPERSEDED FOR THE CLAUDE SEAT ONLY, 2026-07-31, by UCCA-VERDICT-BRIDGE-PER-ELEMENT-2026-07-31 §4 — R2 object listing over the REST API works, so record counts and marker-set completeness are provable from that seat: 43 calibration records and exactly 2 failure markers, the "no third exists" §7 called unproven and unprovable. These limits remain TRUE of Alex's seat and its credentials, and this document's bytes are untouched. Its §5 seal-verification procedure, §6 index.lock diagnosis and §8 landmines are unaffected. ground/UCCA-TM-2026-07-30-TECH.md
UCCA-TM-2026-07-30 Session-close baton for Thu 30 Jul 2026 — CURRENT SESSION REFERENCE, read first at cold start. The window that finished window 1. Step zero verified on bytes, then the bridge run executed AND replicated — four sealed records, two models, 43 elements each, all four signatures re-derived and RSA-PSS-SHA256 verified. GLM is DETERMINISTIC on this suite (43/43 emitted states identical across two runs; only cost_usd moved, which itself proves the path re-inferred rather than replayed); nemotron moved on two elements, both in its favour; and the over-claim counts reproduced exactly — GLM 4 and 4, nemotron 2 and 2, the same probes each time, so the per-model direction claim survives rather than being withdrawn. THE LICENSING CONDITION FIRED: ops-scope-incident-locations-neg and ops-nearmiss-fire-exits are wrong in all four runs of both architectures — two independent reasoners, four for four, disagreeing with keys the authoring seat wrote, which is the pre-committed trigger for an outside review on the keys, not the engine. The first-ever fabricated anchor hinged on ONE CHARACTER — a sentence-terminal full stop that simultaneously broke verbatim correspondence and made the quote byte-identical to the obligation; it did not recur, and is downgraded from defect class to incident (still first-of-its-kind, still caught by the fence). PROCESS FAILURE, OWNED: the trigger card shipped in the same message as the blocking filing relay, the runs beat the pre-registration to the repo by 12 and 4 minutes, and that note is filed verbatim and withdrawn on its own terms. Standing rule from it: a trigger card never ships in the same message as a filing relay it depends on. Also: read-only repo mount gained on the Claude seat (live substrate still via Alex/console); AI-Gateway position reversed, captured not ruled. SUPERSEDED 2026-07-30 by UCCA-TM-2026-07-30-B — no longer the current session baton; read UCCA-TM-2026-07-30-B first. Bytes untouched, still verify to 3fec9f6d…. ✎ Its §6 queue is DISCHARGED THROUGH ITEM 1 and re-sequenced: item 1 (step zero + this filing) executed — c491caf verified on bytes at UCCA-FILING-BRIEF-BATON-AND-CAPTURE-2026-07-30 §1, all legs matching. Its §7–§8 carry in full into UCCA-TM-2026-07-30-B §9. CORRECTION carried from UCCA-TM-2026-07-30-B §6: its §5 line describing the repo mount as read-only is wrong — the bridge exposes a write path, read-only was a discipline and not a constraint, and Tim lifted that discipline on 2026-07-30T10:00Z; the Claude seat now writes staged documents to the workspace root directly. Rule #1 is untouched — the bridge reaches the filesystem, never Cloudflare. · Filed 2026-07-30 as the then-current session baton. Supersedes UCCA-TM-2026-07-28-B. Its §6 step-zero verification of 0afb868 was executed at this filing — all three blobs and both prior batons re-hashed unchanged. Reconfirm ALL live state via Alex next window — do NOT assert live from this baton. Verifies to 3fec9f6d…, 82 lines. ground/UCCA-TM-2026-07-30.md
UCCA-VERDICT-BRIDGE-RUN-2026-07-30 Verdict — the first bridge-v1 runs, both models, read under the pre-registered dual grammar. Two sealed records, 43 elements each, identical accuracy_rate (39/43, 0.9069767…) reached by disjoint failure profiles — GLM 0 under-claim / 4 over-claim / 0 contract failure; nemotron 1 under-claim / 2 over-claim / 1 contract failure. The suite built to expose under-claim measured 6 over-claims against 1 under-claim — the corpus found the opposite of what it was designed to find, and the opposite is the more dangerous direction. THE FINDING IS NOT A NUMBER: nemotron emitted, as its verbatim evidence, a byte-identical copy of the OBLIGATION TEXT, truncated at the exact point the material stops matching the requirement and re-terminated with a full stop — the engine proving the requirement is met by quoting the requirement. The v1.1 fence caught it not_verbatim; first non-zero fabricated_anchor_rate in the ledger. SECOND FINDING: on the SCOPE axis both architecturally distinct models fail together and agree AGAINST the author's key, which puts the key — not only the engine — in question. Four rulings sought (§9). ISSUED 2026-07-30. Records read: default/calibration/2026-07-30T06:28:41.657Z.json (GLM, body e03edf8a…) · default/calibration/2026-07-30T06:36:41.392Z.json (nemotron, body 0a77d985…); both seals re-derived and RSA-PSS-SHA256 verified against the live v1 key. ⚠ FLAGGED, BYTES UNTOUCHED — superseded in part by the replication of 2026-07-30: its §3 per-model direction claim SURVIVES on the over-claim axis; its under-claim finding is WITHDRAWN; its contract-failure finding is DOWNGRADED to incident (non-recurrence downgrades class → incident, never to nothing, per UCCA-NOTE-RUN-PREREGISTRATION-BRIDGE-REPLICATION-2026-07-30 §3). The document is flagged, not amended — read it with this row. sme_validated: false; no figure quotable as accuracy or engine quality. Verifies to 0f89fc10…, 145 lines. ground/UCCA-VERDICT-BRIDGE-RUN-2026-07-30.md
UCCA-NOTE-RUN-PREREGISTRATION-BRIDGE-REPLICATION-2026-07-30 Pre-registration — the bridge-v1 replication pair. Occasioned by a finding off the existing ledger, not off theory: the engine is measurably NON-DETERMINISTIC at temp=0finance-dense-v1 × GLM returned 0.914/15-TRACED at 04:13 and 0.857/17-TRACED at 04:18 on 2026-07-27, five minutes apart, same code, same suite; spread 0.800–0.914 across six runs. A 2-element difference between models cannot be read as directional when the process itself moves by four. Fixes, before either record exists, that the unit of comparison is element identity, never the rate — two records scoring 39/43 by different elements are a disagreement, not a replication — and pre-commits the outcomes for the SCOPE pair and the contract failure. §6: n=2 is a reproducibility spot-check, NOT a variance estimate, stated in advance precisely because the temptation will exist afterward. WITHDRAWN AS PRE-REGISTRATION 2026-07-30 — its own §7/status clause is SELF-EXECUTING and executed. Both replication records — default/calibration/2026-07-30T07:10:34.264Z.json and …07:18:00.100Z.jsonsealed BEFORE this note reached the repo, so the timestamp property it existed to hold was never obtained. Per its own words it is "withdrawn, not back-dated." Bytes filed verbatim and unaltered — the withdrawal is recorded here, never by editing the document. Authorship precedes the records and is ATTESTED, NOT PROVEN. Its §3 element-level readings were unseen by Claude at the time the records sealed and remain citable on that narrower basis; its aggregate-level readings are NOT. Verifies to 3f525ee7…, 75 lines. ground/UCCA-NOTE-RUN-PREREGISTRATION-BRIDGE-REPLICATION-2026-07-30.md
UCCA-CAPTURE-MODEL-ACCESS-AND-SELECTOR-2026-07-30 Capture — multi-model access via Cloudflare AI Gateway, and the model selector under thinking. Records a position change, not a ruling: ADR-0004's no-gateway clause was written against flat-fee resellers with a structural incentive to cache; Cloudflare bills consumptively and has no such incentive. Claude's accepted sharpening: the residual risk was never adversarial economics but CONFIGURATION DRIFT — caching and retries are advertised, configurable features, so the exposure is a setting that is on, gets turned on, or moves default after a product update; the same failure class that bit this project twice this month. Five unchanged conditions (§3), of which cache-off is load-bearing, not paperwork: behind a cache the two finance-dense runs return identical bytes and a replication comes back element-identical — a cache does not merely add noise, it manufactures the most flattering available answer. Selector shape (b) a dated, drift-caught MODEL_REGISTRY on the proven PROBE_SUITES pattern — recommended, not built; carries the KV-republish-is-a-CI-step landmine. §5 names the unsolved single-slot contention. CAPTURED 2026-07-30 — NOTHING RULED. Authorises no build, no deploy, no trigger. This row is NOT an ADR-0004 amendment and must not be read as one — §6 is explicit that the gateway clause must be amended by changelog line or superseded by a new ADR before any of §3–§5 is actionable, and "a session agreement is not an amendment." The measurement lane stays paused. Two items flagged unverified and not assumed (startup-credit coverage of partner-model inference; engine-owned Anthropic key provisioning). Verifies to 75f05966…, 68 lines. ground/UCCA-CAPTURE-MODEL-ACCESS-AND-SELECTOR-2026-07-30.md
UCCA-BRIEF-PLAY-AAB-02 Build brief — UCCA Online Android App Bundle (AAB). The Capacitor wrapper for ucca.online: a placeholder wrapper, authored solely to preserve Play developer account currency — not a product surface. It is the source of authority for the SECRETS block in mobile/ucca-online-android/.gitignore, which cites this doc_id at §4 and is now committed at 8ef04b7e… (surfaces, 59 files) — the brief the shipped ignore-rules answer to. FILED 2026-07-30 — NOT RE-VERIFIED. Tim ruled the filing without a content review; the bytes are filed verbatim and unaltered, and nothing in this brief has been checked against current reality at filing time. Recovered from ~/Downloads, authored 2026-07-16 (frontmatter untouched — the authored date is the original, not the filing date). Filed to ground/ because no brief/ directory exists in the current tree and layer: brief resolves there by precedent. Records by digest, without filing them (per the UCCA-BUILD-BRIEF-HARD-TRUE-POSITIVES-2026-07-26 treatment of its unfiled drafts): the superseded alex-brief-ucca-online-aab.md (71dd85cd…), marked by this brief "WRONG on approach; do not build from it", and TIME-MACHINE-play-dormancy-2026-07-16.md (711e8f12…) — both confirmed present on disk at ~/Downloads/app/ and referenced nowhere in docs/, at filing time. Verifies to 0318e2af…, 139 lines, 8,147 B. ground/UCCA-BRIEF-PLAY-AAB-02.md
UCCA-TM-2026-07-28-B Session-close DELTA baton for Tue 28 Jul 2026 (B) — CURRENT SESSION REFERENCE, read first at cold start. The post-baton tail — small and deliberate. Nothing built, run or crossed since TM-28. Two things happened. The close-relay EXECUTED (docs 1d5c2e2 — pre-registration and TM-28 filed at their exact seals, TM-27-F demoted bytes-untouched; engine 1fcae5c — Seam 3b landed two-sided: real tab flags nothing, rigged tab flags exactly ['scope'], and a flag-everything detector fails too, 102 green). And TIM RULED THE ROADMAP: revenue first — the system working in totality before refinement. Three windows — (1) the bridge run exactly as pre-registered, after which the measurement lane PAUSES; (2) the in-house end-to-end beta loop, one public unit forward through the live spine and the engine's own output diagnosed backward, sealed UCCO, zero client material, no fence, the parked worlds/rtopacks fossil question answered by running it; (3) the RTOpacks beta as a repeat, not a build. Terms at UCCA-CAPTURE-ROADMAP-BETA-2026-07-28 (60fcedd3…). The two-tier verification discipline is PROPOSED, NOT RULED — it waits on Tim's explicit tick. Tim's zero-usage homework: the tick, and carrying the client ask to RTOpacks. SUPERSEDED 2026-07-30 by UCCA-TM-2026-07-30 — no longer the current session baton; read TM-2026-07-30 first. Bytes untouched, still verify to e0fb36ca…. ✎ Its §3 queue is DISCHARGED THROUGH ITEM 3 and re-sequenced: item 1 (step zero + this filing) executed at docs c73caec; item 2 (Tim's tick on the two-tier discipline · the RTOpacks client ask) still open and carried, with the tick now recommended for parking since the repo mount collapsed the cost that motivated it; item 3, WINDOW 1 — the bridge run, EXECUTED AND REPLICATED to four sealed records and a verdict (UCCA-VERDICT-BRIDGE-RUN-2026-07-30, 0f89fc10…), closing the window and starting the measurement pause. Items 4–6 (windows 2 and 3, and the paused lane) carry unchanged into UCCA-TM-2026-07-30 §6. · Filed 2026-07-30 (authored 2026-07-28) as the then-current session baton. Supersedes UCCA-TM-2026-07-28. Its step-zero byte-verification of 1d5c2e2 and 1fcae5c was executed and matched at that filing. Reconfirm ALL live state via Alex — do NOT assert live from this baton. Verifies to e0fb36ca…, 49 lines. ground/UCCA-TM-2026-07-28-B.md
UCCA-CAPTURE-ROADMAP-BETA-2026-07-28 Capture — the road to beta processing. Records Tim's roadmap ruling of 2026-07-28: the priority is revenue; get the system working in totality, then come back and make it better — beta processing quality explicitly not the concern at this stage. Three windows: (1) the bridge run as filed, one sitting, banking gate B's measurement and the under-claim baseline, then the measurement lane PAUSES — pricing pass, further calibration suites and corpus work, the moderation and ruling queues, repair_used, new instruments: all deferred on the ledger, none cancelled; (2) the in-house end-to-end beta loop — one public unit of competency run forward through the live spine, then the engine pointed backward at its own generated output, gate → queue → container → reasoner → signed UCCO in R2 in both directions, driven from admin.ucca.online, with zero client material and no fence crossing — and the parked worlds/rtopacks adapter-fossil question answered by running it, the only answer that counts; (3) the RTOpacks beta as a repeat, not a build — their unit choice and material enter as Tim's word or filed crossings, same loop, results back across the fence. Constraint on the record: Fable usage exhausts in roughly five days of seven across both houses, and the scarce resource is thinking capacity, not engine runtime — so windows get fewer, longer, leaner. Never relaxes, beta or not: the fence in full, the engine raises hands and never signs, job rows permanent, e5a98302 always / f95d4537 never, keep-current Terraform, the honest ledger and honest labels (sme_validated: false where it applies). RULED 2026-07-28 — roadmap and measurement pause, by Tim's selected option, verbatim label "Adopt, capture it". §4's two-tier verification discipline is PROPOSED, NOT RULED — Tier 1 full byte discipline for canon/contracts/sealed records/fence/client-facing/serving deploys, Tier 2 spot-verification and bigger seams for mechanical work; it takes effect on Tim's explicit tick and not before. Does not reopen the baton, authorise any trigger/crossing/deploy, or touch the bridge-run pre-registration. Filed 2026-07-30. Verifies to 60fcedd3…, 43 lines. ground/UCCA-CAPTURE-ROADMAP-BETA-2026-07-28.md
UCCA-TM-2026-07-28 Session-close baton for Tue 28 Jul 2026 — CURRENT SESSION REFERENCE, read first at cold start. The bridge-lane window. Opened on a tech TM carrying one false line — "no probes-bridge-v1.json on disk, it does NOT exist yet" — which a live read at the brief's own delivery path falsified in the first hour: the fixture existed, four-round-reviewed, waiting since the 26th's frame-break. The queue item changed from AUTHORING to RESUMPTION on that read, and the lane then ran end to end in one window: resume brief RULED (0.1–0.4) → Seam 0-R (zero keys changed, three defects filed) → all three ruled and fixed → delta review (one disagreement filed, ruled against, recorded) → Seams R and 1–5 shipped. bridge-v1 is registered and live: the first corpus in the project's history that can construct a false negative. SUPERSEDED 2026-07-28 by UCCA-TM-2026-07-28-B (filed 2026-07-30) — no longer the current session baton; read TM-28-B first. Bytes untouched, still verify to f7842ba8…. ✎ Its §1–§2 stand as the window's record and are not restated; its close-relay is EXECUTED and byte-verified at docs 1d5c2e2 / engine 1fcae5c; its §3 items re-sequence under the roadmap ruled at UCCA-CAPTURE-ROADMAP-BETA-2026-07-28; its §4–§5 ledger points and landmines carry in full. · Filed 2026-07-28 as the then-current session baton. Supersedes UCCA-TM-2026-07-27-F. Reconfirm ALL live state via Alex next window — do NOT assert live from this baton. Verifies to f7842ba8…, 80 lines. ground/UCCA-TM-2026-07-28.md
UCCA-NOTE-RUN-PREREGISTRATION-BRIDGE-2026-07-28 Pre-registration — the bridge-v1 runs. Fixes the reading rules, the run set, the per-model readings and the mechanics before any bridge record exists — which is the entire point of it, and why it is in the repo before a trigger can fire. Carries ruling 0.1's dual reading committed verbatim: an engine NOT_YET on a bridge -pos records as under-claim relative to the key AND defensible conservatism under the shipped verbatim-only grammar — both sentences fixed while no record exists, so no verdict can post-hoc pick the flattering one. Per-model readings per the per-model calibration law. §4 bars any figure from being quoted as accuracy (sme_validated: false). §6 rides the author-conflict and the citation bar into the verdict. §7 carries the Seam 3b instruction. FILED 2026-07-28, BEFORE TRIGGER ONE — the ordering is the point. The verdict on the runs may read only what this note names; a clean 43/43 sweep would read as "keys agree with this engine on these bytes", never as validation. Verifies to dcf77a47…, 70 lines. ground/UCCA-NOTE-RUN-PREREGISTRATION-BRIDGE-2026-07-28.md
UCCA-TM-2026-07-27-F Session-close baton for Mon 27 Jul 2026 (F) — CURRENT SESSION REFERENCE, read first at cold start. The switcher window. The model-switcher proof ran end to end in one sitting: brief ruled → machinery built and shipped (container v33, admin-api forwarding) → cost probes on both models → pre-registration filed before trigger one → seven mirrored triggers from Tim's hand → verdict on triple-hash-proven bytes. The cost probes killed the list-price cost case: 0.942× measured against 0.345× predicted — a 16-fold forecast error in the flattering direction, caught by measurement before a cent of suite spend, and Model B re-affirmed on the corrected picture. Verdict: the honesty discipline survived the swap — zero fence breaks, full contract, 126/126 both sides — with the two models showing opposite failure directions, demonstrating the per-model law on bytes. Three rulings recorded this window: Model B re-affirmed post-correction ("Proceed with nemotron") · burst ("Records stand, burst declared") · gate C ("Gate C closes"). SUPERSEDED 2026-07-28 by UCCA-TM-2026-07-28 — no longer the current session baton; read TM-28 first. Bytes untouched, still verify to 91fdd9d7…. ✎ §3 item 2, the bridge suite, EXECUTED through Seams 1–5 with the pre-registration delivered; item 1, the RTOpacks requirements, still out with Tim, unchanged; items 3–12 carry. · Filed 2026-07-27 as the then-current session baton. Supersedes UCCA-TM-2026-07-27-E. Reconfirm ALL live state via Alex next window — do NOT assert live from this baton. Verifies to 91fdd9d7…, 56 lines. ground/UCCA-TM-2026-07-27-F.md
UCCA-TM-2026-07-27-E Session-close baton for Mon 27 Jul 2026 (E) — CURRENT SESSION REFERENCE, read first at cold start. Delta baton, small and deliberate. TM-27-D's close-relay is executed and verified at docs 401d6de — the next window opens on work, not housekeeping. Tim re-ruled the opening: it starts with RTOpacks and their first-run requirements — the client conversation the five-gate DoD proposal was built for — with the switcher run brief (Model B @cf/nvidia/nemotron-3-120b-a12b) immediately behind it. Alex's context-parity note banked for that draft. SUPERSEDED 2026-07-27 by UCCA-TM-2026-07-27-F — no longer the current session baton; read TM-27-F first. Bytes untouched, still verify to d2df98c0…. ✎ §3 item 2, the switcher run brief, EXECUTED THROUGH VERDICT this window — gate C closed by ruling; §3 item 1, the RTOpacks conversation, OPENED (five gates framed, the client ask now with Tim); items 3–10 carry. · Filed 2026-07-27 as the then-current session baton. Supersedes UCCA-TM-2026-07-27-D. Reconfirm ALL live state via Alex next window — do NOT assert live from this baton. Verifies to d2df98c0…, 41 lines. ground/UCCA-TM-2026-07-27-E.md
UCCA-TM-2026-07-27-D Session-close baton for Mon 27 Jul 2026 (D) — CURRENT SESSION REFERENCE, read first at cold start. The reorientation window. Corporate closed end-to-end in one sitting — brief drafted on bytes (27 pairs, parser-verified), Tim ticked, one seam commit a56022a, verdict CLEAN proven by committed-blob hashes; the out-of-scope catch (ucca.com.au live-serves the engine's trust.txt, self-contradicting since March) confirmed on live fetches and ruled: remove at release. Then the wheel turned: product first, the switcher named, priority drift owned. Engine seam read at c5ba1e8 — the throat is BUILT (per-call provider+model, three executors, per-provider repair, usage capture), selection is PINNED to constants, and no model but GLM-5.2 has ever run through it. Recon banked: 61 enumerable models, gaps stated not filled. Model B RULED @cf/nvidia/nemotron-3-120b-a12b; the run brief drafts COLD next window and is the queue head. SUPERSEDED 2026-07-27 by UCCA-TM-2026-07-27-E — no longer the current session baton; read TM-27-E first. Bytes untouched, still verify to 3fdb55f1…. ✎ Its filing was verified at docs 401d6de in the same sitting, so the next window's step zero is pre-done. §3 re-ordered by Tim: the RTOpacks first-run requirements conversation now opens the next window; the switcher run brief (Model B, @cf/nvidia/nemotron-3-120b-a12b) sits immediately behind it. Everything else carries. · Filed 2026-07-27 as the then-current session baton. Supersedes UCCA-TM-2026-07-27-C. Reconfirm ALL live state via Alex next window — do NOT assert live from this baton. Verifies to 3fdb55f1…, 60 lines. ground/UCCA-TM-2026-07-27-D.md
UCCA-BUILD-BRIEF-CORPORATE-REAUTHOR-2026-07-27 Build brief — corporate re-author against capture §4. Agent/processor split on all five held pages: the Pty Ltd is the authorised local sales agent, UCCA Inc (Delaware) is the processor; the AU→US disclosure inverted the old "processed in Australia" claim; agent-domain mailboxes (@ucca.com.au); IP and the UCCA® mark re-attributed to UCCA Inc (footers become © UCCA Inc); disclosure scope narrowed to ucca.com.au; careers honesty fix. 27 OLD→NEW pairs, copy-only, no design change, RTOpacks appears nowhere before or after. FILED — RULED R1 · R2 · R3 · R4 in-session (Tim, 2026-07-27; labels verbatim in §1) — EXECUTED at surfaces a56022a, one seam commit, 5 files +64 −51 — verdict CLEAN (UCCA-VERDICT-CORPORATE-REAUTHOR-2026-07-27). No deploy: corporate stays HELD until its own release brief. Verifies to fe1464cd…, 548 lines. ground/UCCA-BUILD-BRIEF-CORPORATE-REAUTHOR-2026-07-27.md
UCCA-VERDICT-CORPORATE-REAUTHOR-2026-07-27 Verdict — corporate re-author at a56022a: CLEAN on bytes. The commit is exactly the brief applied to 32f2184 — nothing more, nothing less — proven by hashing the five committed blobs device-side against expectations computed locally from the pre-edit bytes plus the 27 pairs; all five equal, security.txt blob untouched. Carries the trust.txt ruling — ucca.com.au live-serves the engine's machine identity (org.domain=ucca.online, US-DE, security@ucca.online) two paths from a security.txt declaring the agent: "Remove at release" (Tim, 2026-07-27, label verbatim) — and the consolidated release checklist (§3): brief §6.1–6.5 plus trust.txt removal, security.txt:42 alignment, the dead ops.ucca.online footer link, census 5.2b leftovers, home-footer © sweep, engine-side ucca.online security.txt. §4 banks a bridge landmine: re-staged same-path files read stale through the mount cache — committed-blob hashing is the standard. FILED — CLEAN on committed-blob hashes. Corporate deploys on the release brief and not before. Verifies to 9b4aa745…, 45 lines. ground/UCCA-VERDICT-CORPORATE-REAUTHOR-2026-07-27.md
UCCA-TM-2026-07-27-C Session-close baton for Mon 27 Jul 2026 (C) — CURRENT SESSION REFERENCE, read first at cold start. The register-hygiene window: four sub-rulings in one sitting, one commit, verdict CLEAN on bytes. The A-series inventoried end-to-end for the first time (A1–A26 Fable pass · A27–A29 universality test · A30 in-repo); canon/build-ledger.md exists and its convention MINTED Class G; the ADR log runs 0001–0015 gap-free; ADR-0015 has its file; the repo finally holds the three source documents its canon already cited — the universality test filed inseparably from its correction. One relay defect (a covering block with blank rulings) STOPped clean and cured at the mechanism: rulings are captured in-session first, blocks go out COMPLETE. One fence incident logged — FI-05, RTOpacks bytes injected into a UCCA session by tooling: flagged, untouched, no crossing; the injection path stays OPEN and is Tim's to close. Corporate re-author is the queue head. SUPERSEDED 2026-07-27 by UCCA-TM-2026-07-27-D — no longer the current session baton; read TM-27-D first. Bytes untouched, still verify to e0d82326…. ✎ §3 item 1, the corporate re-author, DISCHARGED at surfaces a56022a by UCCA-BUILD-BRIEF-CORPORATE-REAUTHOR-2026-07-27, verdict CLEAN; §3 item 8, the second Workers-AI model, PROMOTED to queue head as the switcher proof — Model B ruled @cf/nvidia/nemotron-3-120b-a12b. · Filed 2026-07-27 as the then-current session baton. Supersedes UCCA-TM-2026-07-27-B (its §3 item 1, register hygiene, DISCHARGED at ec9f015; item 2 corporate re-author promoted to queue head; remaining items carried). Reconfirm ALL live state via Alex next window — do NOT assert live from this baton. Verifies to e0d82326…, 59 lines. ground/UCCA-TM-2026-07-27-C.md
UCCA-TM-2026-07-27-B Session-close baton for Mon 27 Jul 2026 (B) — CURRENT SESSION REFERENCE, read first at cold start. The session that took the queue head and broke the loop: one calibration pass under the ruled semantics, pre-registered before any record existed, seven triggers from Tim's hand, and a verdict that for the first time did not dissolve on contact with the records. Window ~03:30–05:30 UTC. What happened: TM-27 was found NOT in the repo at open — the prior window's close-relay never executed — and was folded into the run brief's §8 rather than chased separately; Alex caught the covering-digest gap (Tim's relay carried no digest, the fourth in a row) and refused to treat disk bytes as ruled bytes until the digest was confirmed — cured at the mechanism, covering lines are now pre-written with the digest in them; the §6 fork dissolved by observation (the admin console was already live at 2badc53, since Pages carries commit identity where Workers carries none), so neither branch executed, no deploy of any kind this window, corporate untouched; seven triggers, one at a time, seal-confirmed by GET between each, failures/ re-confirmed as the two 2026-07-24 markers after every trigger, seven records and no eighth, no re-trigger needed; verdict PASS-STABLE at 8e8c70c. Run-lock exit criterion 6 DISCHARGED — banner named the posted suite mid-seal, Run withdrawn, gate block rendered, and Tim's word verbatim: "all worked find from the ui perspective." §3 owed, cold-start order: (1) register-hygiene ruling — now the queue head, cheap and one sitting (no build-ledger file, A-numbers on prose greps; ADR-0013/0014 placement; ADR-0015 without a decisions/canon/ file); (2) corporate re-author against capture §4; (3) the synthesis ruling queue — obligation-level classification → verdict grammar → absent failure modes; (4) SHARPENED by this pass — the under-claim direction: every error across 126 elements was an over-claim, and the other direction stays structurally untestable until hard true positives exist; (5) moderation, where the basis-class test is dead (collinearity — the axis was the key) but the oscillator evidence is now richer; (6) the parked fence-adjacent items; (7) A30 · frontiers-copy sweep · citation verification; (8–9) carried, incl. the standing note that the www "302 downgrade" does not exist — do not re-report it. Landmines carried: one-at-a-time is operating law while /calibrate's lock is per-process and instances = 2; a blank /calibrate body silently runs v2 — every trigger names its suite. SUPERSEDED 2026-07-27 by UCCA-TM-2026-07-27-C — no longer the current session baton; read TM-27-C first. Bytes untouched, still verify to 8fbce716…. ✎ superseded by TM-27-C on filing; §3 item 1 register hygiene DISCHARGED 2026-07-27 at ec9f015 by UCCA-RULING-BRIEF-REGISTER-HYGIENE-2026-07-27, verdict CLEAN; corporate re-author now queue head. · Filed 2026-07-27 as the then-current session baton. Supersedes UCCA-TM-2026-07-27 (its §3 item 1 — the calibration pass — DISCHARGED at 8e8c70c, run complete and PASS-STABLE filed; item 3, register hygiene, promoted to queue head; items 2 and 4–10 carried). Reconfirm all live state via a fresh read — do NOT assert live from this baton. sha256 8fbce716f3daa4d6eab15a6b6fe23e3b6348cb4f19cb31d16d6af4df7470a1f6 ground/UCCA-TM-2026-07-27-B.md
UCCA-VERDICT-CALIBRATION-PASS-2026-07-27 Verdict — the calibration pass under the ruled semantics: PASS-STABLE. Seven records, 126 elements, and every one states in the §3 locked vocabulary — no record forced a category the pre-registration did not contain. "For the first time in this programme's life, the reading of a calibration result did not dissolve on contact with the records — because for the first time, what the reading means was ruled before the records existed." Filing preceded trigger (brief filed 0b5e3d1; trigger 1 at 03:54:54Z), so the reading binds. §3.2 NEVER ARMED: five gate-element appearances across the pass — avi-ungrounded-tcds, pha-ungrounded-spec, fin-ungrounded-suitability, fin-aml-riskrating-annex ×2 — all NOT_YET_TRACED with zero anchors, so the any-vs-every discrimination never ran; beyond requirement, all 55 anchors emitted across the pass scanned with the engine's own _marker_hits: zero carry any marker. §3.3 resolved on its committed second branch: fin-aml-cdd-uptodate-cycle is TRACED 4/5 across post-gate runs — a NOT_YET occurred, so it joins the oscillator set and the "stable shift" character the Type-A verdict §5 flagged is dead; the single 24 Jul baseline was one draw from an oscillator, not a contradicted constant. Reported as frequency, resolved by nothing. Reproduction: pharma (×4), finance (×4), defence (×2) and defence-contrast (×2) are element-identical across every post-gate run of their suite — 45 elements reproducing exactly, disagreements included; movement is confined to finance-dense-v1's five known elements across five runs, no sixth has ever moved. THE SHARPEST NEW FACT: fin-bestex-fee-latency-multihop sat in the stable-error column of every prior enumeration for three consecutive runs and moved for the first time in run four — so the stable/oscillating boundary is frame-relative: an element is only "stable" relative to the runs observed so far, and three identical readings did not bound the fourth. It states cleanly in the locked vocabulary (held → moved, with frequencies) and so does not break PASS-STABLE, but it hardens stability does not imply correctness into stability is not even a fixed property of an element — any future design partitioning elements into "stable" and "oscillating" as kinds is building on this pass's counter-example. Direction, universal: all 16 disagreeing element-readings out of 126 are TRACED where the key expects NOT_YET; zero instances of the converse — a sentence §3.6 forbids reading as reassurance, since the corpus cannot construct a false negative and the under-claim direction remains untested, not vindicated. Arithmetic closes without residue: every aggregate reconciles against its disagreement list, and the five-run dense reconstruction reproduces all historical aggregates exactly. What may be cited: the distributions as distributions, the dispositions as v1.2 claims — no figure here is engine performance and none may become one by citation (class-2/3 keys sme_validated: false, class-1 author-keyed). Ran with instances = 2 over a per-process lock, so one-at-a-time was load-bearing and held — carried as operating law until the route serialises globally. ISSUED 2026-07-27 — PASS-STABLE. Issues under the run brief's §3 and nothing wider; closes that run set as complete at seven triggers. Nothing mints — measurement, not build. Discharges: TM-27 §3 item 1 (the queue head) and the Type-A verdict §5's owed dense re-runs. Residue unchanged and unlaundered: the correctness quarantine, SME validation, bridge-v1 still unregistered (still the only path to testing the under-claim direction), the admin-api hop, the eight unexercised markers, and the register-hygiene ruling — now the queue head. Run-lock exit criterion 6 OBSERVED, not discharged — awaiting Tim's one-word confirmation. sha256 ee3c96dd550f3c2ca481b7a112c2b530dfab169bbdf06a04b08e0a58dc8d00e9 ground/UCCA-VERDICT-CALIBRATION-PASS-2026-07-27.md
UCCA-RUN-BRIEF-CALIBRATION-PASS-2026-07-27 Run brief + pre-registration — ONE calibration pass under the ruled semantics: the first measurement in this project's history whose reading is defined BEFORE it is taken. Seven triggers across the six-suite instrument (finance-dense-v1 twice, discharging the Type-A verdict's §5 owed re-run). Nothing in the engine changed for this — v1.2 was canon-only, so the same container runs the same corpora and "no future reader may cite this pass as a test of a code change." The reading is committed at §3 before any record exists. Units are v1.2 claims: a TRACED emission asserts anchored responsiveness on the declared basis, the verdict grades record-vs-key, states each suite's key status, and never converts agreement into engine performance (finance-dense-v1 is class 3 sme_validated: false). §3.2 arms a STOP: if a gate element emits TRACED while every anchor carries a marker, that is gate-failure shape and the pass halts — but if any anchor is marker-free the gate is correctly inert and it is variance, resolved on anchor bytes by the engine's own _marker_hits, not by argument. §3.3 reads fin-aml-cdd-uptodate-cycle as a frequency across five post-gate records and forbids resolution by majority — moderation's forbidden move, forbidden here too. §3.5 IS THE FALSIFICATION CRITERION and the strongest thing in the brief: the verdict may use only a locked vocabulary, and if any record cannot be honestly stated in it, the pass has FAILED to stabilise the reading — that finding, not any number, is the result. PASS-STABLE or PASS-UNSTABLE, stated plainly; a new category goes to Tim as a proposed ruling, never invented inside a verdict. §3.6 caveats ride every citation: the correctness quarantine is not lifted and nothing here launders it; the corpus is tilted by construction (37/49 expected-NOT_YET are honesty_tempting traps; every expected-TRACED is verbatim); the under-claim direction remains untestedprobes-bridge-v1 is on disk, unregistered, and NOT run; fabricated-anchor 0.0 is consistent with the failure mode, not reassurance against it. §4's scope guard: exactly seven triggers, one re-trigger per technical failure on Tim's word, "analysis has no natural stopping point; this pass does." Every trigger names its suite — a blank /calibrate silently runs v2. §7 records on bytes: the container's /calibrate is single-flight (_CALIB_LOCK; a second POST short-circuits to 202 already_running), part-answering the run-lock brief's carried route question — with the honest caveat that the lock is per-process and the live guarantee rests on instance count. Nothing mints — this is a measurement; Class B mints on build proof only, and the Type-A mint stays its bounded sentence. RULED by Tim 2026-07-27, as drafted, no changes. Filed bytes deliberately keep status: DRAFT in frontmatter — the ruling lives in this register row, per Tim's instruction. §6 fork RESOLVED BY OBSERVATION — no deploy of any kind: the admin console is already live at 2badc53 (Pages ucca-admin, deployment ec7604c7, Production/main), which is run-lock U1–U3, so fork A had nothing to ship and fork B's stale-console premise was false; run-lock exit criterion 6 rides this session on Tim's confirmation. Corporate untouched under every reading. sha256 a9aede7175c9c5f60f2807436e0ae08cd90cbbc4aff8a2996a84afdcc7e602bc (120 lines) · ✎ EXECUTED 2026-07-27 — seven triggers, complete; no eighth, no re-trigger needed. Verdict: UCCA-VERDICT-CALIBRATION-PASS-2026-07-27 — PASS-STABLE. Bytes untouched. ground/UCCA-RUN-BRIEF-CALIBRATION-PASS-2026-07-27.md
UCCA-TM-2026-07-27 Session-close baton for Mon 27 Jul 2026 — CURRENT SESSION REFERENCE, read first at cold start. The session that took the deploy word and had the gate prove its worth on first contact. Tim's word, verbatim: "ok yes both are strong marketing words but honest is honest wich is beter even on this promo page. agreeded. make the changes." THE GATE FIRED AND WAS RIGHT TO EXIST: both public sites were ~4 months stale — marketing baseline 2026-03-31, corporate 2026-03-04 — and Cloudflare carries no commit identity for either, so the baseline is timestamp-only, a limitation stated each time rather than papered over. The release then split on Tim's ruling. Marketing: the precondition was confirmed twice and the rider dissolved — the live D1 binding was already fb6ddc43…, so 118da72 was a no-op against live state; the config file had lagged reality by four months, not led it. Deployed ucca-site 23dbb8b0… at 23:21:50Z, verified 7/7 by key across all seven locales. Corporate: HELD, and the hold changed character — this seat flagged the five never-published pages as wrong-house material (every page legally United Central Colleges of Australia Pty Ltd / ABN 59 168 872 535 / QLD, with zero UCCA Inc anywhere), which produced the corporate-structure capture and turned a staleness hold into a re-author requirement. Instrument grades settled by conduct, not assertion: the reported www https→http downgrade does not reproduce — tested rather than transcribed; HSTS is present and both HTTP entry points 301 up. The real item is duplicate apex/www content with no canonical redirect, SEO-low. The bytes-over-bridge mechanism is now three-for-three — every "brief not on disk" stop this week resolved by conduct at ea198d9, both documents verified at source before filing. §3 owed, cold-start order: (1) one calibration pass under the ruled semantics — the queue head, "the loop breaks when something ships"; (2) corporate re-author against capture §4; (3) register-hygiene ruling (no build-ledger file; ADR-0013/0014 placement; ADR-0015 has no decisions/canon/ file); (4) the synthesis ruling queue; (5) the parked fence-adjacent worlds/au-vet/rtopacks/** census, evidence sharpened; (6) A30; (7) NEW — an assertion-level sweep candidate: live marketing frontiers copy asserts "the agent either holds verified capability or it does not", which is the same satisfaction shape one layer out, Tim to rule whether/when; (8) citation verification; (9–10) carried, incl. the standing note that the www "302 downgrade" does not exist — do not re-report it. SUPERSEDED 2026-07-27 by UCCA-TM-2026-07-27-B — no longer the current session baton; read TM-27-B first. Bytes untouched, still verify to 9f432f97…. · Filed 2026-07-27 as the then-current session baton. Supersedes UCCA-TM-2026-07-26-F (its §3 item 1, the deploy word, DISCHARGED for marketing at version 23dbb8b0/23:21:50Z and TRANSFORMED for corporate into the re-author item; item 2 — the calibration pass — carried unchanged as the queue head). Reconfirm all live state via a fresh read — do NOT assert live from this baton. sha256 9f432f9771e8b65795caa1e5f41b28623006bc3c85bcbf525408c9db0fee7a7d · ✎ §3 item 1 (one calibration pass under the ruled semantics — the queue head) DISCHARGED 2026-07-27 by UCCA-VERDICT-CALIBRATION-PASS-2026-07-27. The register-hygiene ruling (item 3) is now the queue head. ground/UCCA-TM-2026-07-27.md
UCCA-DEPLOY-BRIEF-SATISFACTION-WORDING-2026-07-26 Deploy brief — release the ruled principles wording to the live public sites. Its §1.3 RIDER GATE FIRED, and firing is the result worth recording. Tim's deploy word, verbatim: "ok yes both are strong marketing words but honest is honest wich is beter even on this promo page. agreeded. make the changes" — releasing the hold recorded on both wording-brief rows, and covering the wording change only. The gate caught what the word could not have anticipated: both live sites were roughly four months stale, not one commit behind. Live baselines read from Cloudflare (which carries no commit identitySource: Unknown/Upload, Message: -, so baseline is established by deploy timestamp, a stated limitation of the read): marketing 8b0a35d9 deployed 2026-03-31, corporate a5ade536 deployed 2026-03-04. Rider enumeration: marketing 3 commits (the two wording + 118da72 D1 region migration), corporate 4 (the two wording + af18908 + 61f10d9, a 54-file restore the brief did not anticipate). MARKETING — RELEASED. Tim's precondition — "confirm the live D1 binding is fb6ddc43" — confirmed twice, from the bindings and settings endpoints: live DB → fb6ddc43-e0b9-4ca8-b1c7-b1d36aa573df, identical to what 32f2184 ships, so 118da72 was a no-op against live state (it corrected the config file from the stale 0efa8970… to the id the worker was already bound to). Deployed ucca-site version 23dbb8b0-29fc-4c11-ade9-018451c8caaa at 2026-07-26T23:21:50.718Z UTC, from 32f2184; bindings after: env.DB (engine-db) · env.ASSETS; live on ucca.online + www.ucca.online. §3 verification 7/7 by key, on the live site: en · ja · ko · zh-TW · de · fr · vi each verbatim-match the 32f2184 string, with every old satisfaction rendering and every old "No inference" rendering gone. ✎ Verification note worth keeping: the first pass probed /zh/ and got a 200 with an English-lang page and no Chinese — read as a mismatch. The declared locale code is zh-TW; /zh/ is a non-route that answers 200. Checking by key from the source rather than by a guessed URL is what caught it — the localisation lesson one layer out: I checked the route I assumed, not the route the code declares. CORPORATE — HELD.www note, verified this session and it does NOT reproduce as described: there is no https→http downgrade on www.ucca.onlinehttp://www and http://apex both 301 up to HTTPS, HSTS max-age=63072000; includeSubDomains; preload present, and https://www.ucca.online/ answers 200 directly with no redirect. What is real and different: www serves byte-identical content to the apex (118,896 bytes both) with no canonical redirect — duplicate content on two hostnames, an SEO/canonicalisation item, not a security one. Recorded as measured rather than as relayed. RELEASED (marketing) / HELD (corporate) — 2026-07-26. Marketing live at version 23dbb8b0-29fc-4c11-ade9-018451c8caaa, 2026-07-26T23:21:50.718Z UTC, verified 7/7. Corporate HELD — pre-separation drafts, re-author before release (see UCCA-CAPTURE-CORPORATE-STRUCTURE-2026-07-26): its delta is 54 files / 16,423 insertions including six never-live visitor routes (careers, privacy, terms, security policy, security acknowledgments, [locale]) whose copy predates the ruled entity story. Nothing mints — release of already-shipped copy, not a build event. sha256 03f0657ab85a58796b4c7442fb58e503306b1fbc9fed1bec549c42c4bb6e0b18 ground/UCCA-DEPLOY-BRIEF-SATISFACTION-WORDING-2026-07-26.md
UCCA-CAPTURE-CORPORATE-STRUCTURE-2026-07-26 Capture — the corporate-structure ruling, and why the corporate release stays held. Tim's ruling, dictated in session and recorded verbatim with the Whisper Flow normalisations named ("United Community Colleges"United Central Colleges of Australia Pty Ltd, ABN 59 168 872 535 matching canon; "RTO PAX/PACs"RTOpacks). §2 current legal reality, Tim-attested — he is the authority on his own companies: one Australian company, common directorship with UCCA Inc (Delaware C-Corp), different jurisdictions, a cross-border arrangement. The Pty Ltd holds two roles simultaneously today: local sales agent in Australia for the engine business (UCCA Inc is the processor), and doing business as RTOpacks while RTOpacks is in development — a deliberate cost-saving. RTOpacks conducts no business yet. The operational fence runs AHEAD of legal separation by design — the houses are run as-if independent although one AU company currently wraps the AU side, and nothing here relaxes fence discipline. §3 target end state is intent, not existence — nothing in it exists yet: three entities, RTOpacks Pty Ltd to be incorporated prior to launch. §4 the standing copy rule for ucca.com.au, RULED: (1) never mention RTOpacks, rtopacks.com.au, or the doing-business-as arrangement — any page, any language, at this stage; (2) legal pages name the Pty Ltd in its local-sales-agent role; (3) UCCA Inc (Delaware) is named as the processor, and the cross-border story runs AU → US — privacy disclosure points at the United States processor, not "processed in Australia"; (4) hosting ucca.com.au inside this house's repo and substrate is deliberate and ruled, so apps/corporate leaves the census/disposition list while worlds/au-vet/rtopacks/** and the world_config.py tagline remain on it. §5 carries the redraft spec for the five held pages. CAPTURED 2026-07-26 — records Tim's ruling; rules nothing beyond what he said, builds nothing. This is the reason the deploy brief's corporate half reads HELD: the five held pages are pre-separation drafts and must be re-authored against §4 before release. sha256 4bf29c77fd8decca61f816834b482b05b811ccefa1fb6937b808a66a440baddb ground/UCCA-CAPTURE-CORPORATE-STRUCTURE-2026-07-26.md
UCCA-TM-2026-07-26-F Session-close baton for Sun 26 Jul 2026 (F) — CURRENT SESSION REFERENCE, read first at cold start. The session that opened owing a correction and a ruling, found the correction already executed and verified it clean, then took the ruling. TM-E §4 item 1 was already done at 84250d82 — verified on bytes, relay obviated; residue found and fixed from that seat (the project copy still carried the known-false §5.4). THE RULING WAS TAKEN: put to Tim as a plain-language binary, he selected "the modest promise" and confirmed verbatim — "Agreed, yes. Let's run with the modest promise." Filed at a3b9ed0 as NORTHSTAR-01 v1.2 (Class G): TRACED asserts anchored responsiveness with named exclusions, never satisfaction; NOT_YET_TRACED an honest gap, never non-compliance. Then the canon met the copy: the wording sweep found the public principles block asserting "Capability either meets the standard or it does not… No inference." — the exact verdict the new canon forbids — shipped at 9e970ee; the sweep was under-scoped and Alex caught it (principle_2_desc exists in SEVEN locales; the English-only grep surfaced 2 of 14), Tim ruled "reword the twelve translations too", shipped at 32f2184. DEPLOY HELD, verbatim: "i dont want to break or edit it at this point in time either." Surfaces has no CI, so every commit is repo-only and the live marketing and corporate sites still serve the pre-ruling copy, satisfaction claim intact, in all seven languages — a knowing, ruled state, not a gap. Two more relay file-carry defects (the amendment, then the parent brief — neither reached disk; both caught by digest + RECEIPT-CHECK with zero bytes moved) and cured at the mechanism: artefact bytes now travel the bridge rather than by human file-carry. §3 owed, cold-start order: (1) the deploy word — Tim's trigger, Tim's only, one deploy per app covering 9e970ee + 32f2184; (2) one calibration pass under the ruled semantics — TM-E item 3, now unblocked, the queue head; (3) register-hygiene ruling in one sitting (no build-ledger file exists, so A30 rests on a prose grep with highest-observed A29; ADR-0013/0014 sit in the Ground table rather than the ADR log); (4) then the ruling queue as the synthesis ordered it — obligation-level classification → verdict grammar → the three absent failure modes; (5) the parked fence-adjacent tagline, Tim wearing the RTOpacks hat; (6) A30's assertion-scope surface, riding the gated findings-contract v2 pass; (7) citation verification before any opinion carries weight; (9) native-speaker review of the six locale renderings, low. SUPERSEDED 2026-07-27 by UCCA-TM-2026-07-27 — no longer the current session baton; read TM-27 first. Its §3 item 1 (the deploy word) is DISCHARGED for marketing (ucca-site 23dbb8b0…, 2026-07-26T23:21:50.718Z UTC) and TRANSFORMED for corporate into a re-author requirement against UCCA-CAPTURE-CORPORATE-STRUCTURE-2026-07-26 §4; item 2 — one calibration pass under the ruled semantics — carries unchanged as the queue head; items 3–9 carried into TM-27 §3. Bytes unedited — still verify to the digest below. · Filed 2026-07-26 as the then-current session baton. Supersedes UCCA-TM-2026-07-26-E (its §4 item 1 verified DISCHARGED at 84250d82; item 2 RULED and FILED at a3b9ed0; item 3 now the queue head; items 4–11 carried). Reconfirm all live state via a fresh read — do NOT assert live from this baton. sha256 d5ad50be1c5f86343c81979202f8027ddf245f33df9239ef92bb15a2066546a0 ground/UCCA-TM-2026-07-26-F.md
UCCA-BUILD-BRIEF-SATISFACTION-WORDING-2026-07-26-B Addendum — the twelve translated instances of the principles block reworded to the ruled English meaning (ja · ko · zh · de · fr · vi, across both public apps). Tim ruled verbatim: "reword the twelve translations too." The parent's English-only edit (9e970ee) had left six locales still asserting "capability meets the standard" and still denying inference — the exact claim NORTHSTAR v1.2 §6 forbids — on the same live pages. Shipped at surfaces 32f2184: six locale values per file, twelve instances, each also dropping its rendering of "No inference" and gaining the exact-proof sentence. Discipline held: only the ruled delta changed — every incumbent rendering of "No partial credit. No grey area." and of the compliance-theatre sentence preserved verbatim, including ja's imperfect 「部分的な単位なし」, deliberately not fixed. The standing lesson, and it is the reason this addendum exists: a term-based sweep is blind to the claim expressed in another language — sweep by key/structure, not by vocabulary, whenever the copy is localised. Alex's original sweep found 2 of 14; the miss is owned in his report and endorsed here, as was his refusal to author six languages of public copy unilaterally. The NEW strings are Claude-drafted renderings under Tim's ruling; native-speaker review is an open low-rank quality item, and the incumbents were themselves unreviewed as far as the record shows. Also fixes the relay channel — both brief files delivered over the bridge and byte-verified rather than carried by hand — and disposes the A-number question at §2.6. RULED 2026-07-26; SHIPPED to repo at surfaces 32f2184. ✎ MARKETING RELEASED 2026-07-26T23:21:50.718Z UTCucca-site version 23dbb8b0-29fc-4c11-ade9-018451c8caaa, deployed from 32f2184, all twelve translated instances verified live 7/7 by key (en · ja · ko · zh-TW · de · fr · vi), old satisfaction and old "No inference" renderings gone. CORPORATE STILL HELD — pre-separation drafts, re-author before release (UCCA-CAPTURE-CORPORATE-STRUCTURE-2026-07-26 §4/§5). Original hold, now discharged for marketing only: "i dont want to break or edit it at this point in time either." Release gate and evidence: UCCA-DEPLOY-BRIEF-SATISFACTION-WORDING-2026-07-26. Nothing mints. sha256 3dd1ab3c230ec064669becf22be62a1e380560bd40d735585e00834dbb490e1c ground/UCCA-BUILD-BRIEF-SATISFACTION-WORDING-2026-07-26-B.md
UCCA-BUILD-BRIEF-SATISFACTION-WORDING-2026-07-26 Wording pass under NORTHSTAR v1.2 §6 — the public principles block stops asserting a satisfaction verdict the engine never makes. Shipped at surfaces 9e970ee (English) and completed at 32f2184 (the twelve translations, per the addendum above). The edit keeps the binary — it was never the defect — but binaries on the anchor, which the engine can decide, instead of the standard being met, which it cannot: "Every capability claim is anchored in the evidence or it is not… Each finding carries its exact proof — quoted verbatim from the material, byte-verified — or an honest gap." "No inference" was removed rather than replaced — marketing need not explain the basis ladder, only stop denying it, since §6 admits declared inference as a basis. ⚠ PROVENANCE (§0), not to be flattened: hits 1 and 2 are Tim's rulings ("Reword now", "Park it", both selected verbatim); hits 3 and 4 are Claude's dispositions, stated as defaults and not objected to — correctable at any point. The replacement copy is Claude's draft under Tim's delegation. THREE NON-EDITS RULED AND RECORDED so no future sweep re-litigates them: (1) pack_generator.py:183-187 SURVIVES — it relays the training package's own prescription and directs the judgement to the RTO, the accountable human, which is §6-conformant in substance; (2) the RTOpacks tagline in worlds/rtopacks/config/world_config.py:21 is PARKED as fence-adjacent, not edited — it reads as the client's claim about its own products but renders from this house's substrate, and two questions travel with it for Tim wearing the RTOpacks hat (whose voice is that string; should client copy live in engine config at all). No unilateral edit from this side of the fence. (3) Assertion-scope is ABSENT — proven, not suspected: zero hits for assertion[_-]?scope across engine, surfaces and trust in the 2026-07-26 sweep. The envelope seals provenance only; the what-this-claim-does-and-does-not-assert text that v1.2 §6 ratifies has no shipped home, and is therefore not a rewording item — there is nothing to reword. Ledger honesty: v1.1's amendment-record phrase "surfaced in the UCCO assertion-scope" is design intent, not shipped fact, and the sweep dates the proof of absence. RULED 2026-07-26; §1 SHIPPED (9e970ee + 32f2184). ✎ MARKETING RELEASED 2026-07-26T23:21:50.718Z UTC (ucca-site 23dbb8b0…, English string verified live); CORPORATE HELD — pre-separation drafts, re-author before release. A30 assigned inline for the assertion-scope gap — natural build home is the gated findings-contract v2 pass, sequencing Tim's, later. Caveat carried as given: no build-ledger file exists in the docs repo, so "next free" rests on a prose grep; highest observed was A29. The ledger's absence joins the register-hygiene item for Tim's ruling alongside the ADR-0013/0014 placement. sha256 3df5eba0cf4e615cdd1e97fe5651398b472011fcc8c2c595b184441b1a5e5e98 ground/UCCA-BUILD-BRIEF-SATISFACTION-WORDING-2026-07-26.md
UCCA-AMENDMENT-NORTHSTAR-TRACED-SEMANTICS-2026-07-26 NORTHSTAR-01 v1.1 → v1.2 (Class G) + ruling record — the claim's CONTENT. §6 gains its final piece: the proposition being qualified. The house had ratified the mechanics of a finding (basis, scope, temporal character, strictness, self-currency) without ever ratifying what the finding asserts. Now ruled: TRACED asserts a byte-verified verbatim anchor responsive to this element of the compiled obligation, on the claim's declared basis, relative to the compilation and its enumerated leaf-set — and nothing more, with four standing named exclusions (context/definitions/purpose unresolved; qualifying or defeating material elsewhere unchecked; operational reality unobserved; truth of the material unattested). TRACED never asserts the obligation is met, satisfied or complied with, in whole or in part — satisfaction is the accountable human judgement the engine never performs (FOUNDATION-01 §2). NOT_YET_TRACED asserts an honest gap in the trace — never failure, deficiency or non-compliance. Ratifies the house's own 2026-07-19 scoping (UCCA-TRIUMVIRATE-UNIVERSALITY-TEST-01), which was filed ground reasoning and never ratified — which is precisely why the house forgot it and spent a five-model commission rediscovering it; blind-corroborated 4/4 volunteered across the interpretive-doctrine set (synthesis §3.1). Discharges the standing landmine that ADR-0002 alone cannot answer the verdict-neutrality objection — the semantics now does: textual responsiveness is a domain-free property, legal satisfaction is not, so this single ruling is what makes "universal reasoner" a true description rather than a marketing claim (synthesis §5.4). Wording chosen general — "on the claim's declared basis" — so it is true today with verbatim-only basis and still true when the gated v2 basis field ships. One stone. RULED — Class G, RATIFIED at this commit (NORTHSTAR-01 v1.2). ⚠ PROVENANCE DISTINCTION, carried from the document's own §0 and not to be flattened: the substance is Tim's ruling — put to him as a binary, he selected "The modest promise" and confirmed verbatim "Agreed, yes. Let's run with the modest promise." The remaining drafting resolutions are Claude's under that acceptance, NOT Tim's personal rulings on each (general wording; NORTHSTAR §6 as the home; the NOT_YET_TRACED companion line; the follow-up order) — correctable by Tim at any time. Nothing built; nothing Class B mints here. Frozen findings contract v1 untouched (state.enum unchanged — this defines what the states mean, not the schema); the gated v2 basis build stays measure-first-gated as ruled 2026-07-24. sha256 c1af441eba99e598348c12486958db032d2448765083861b94b22337a996e28a ground/UCCA-AMENDMENT-NORTHSTAR-TRACED-SEMANTICS-2026-07-26.md
UCCA-VERDICT-SYNTHESIS-V3-FILING-2026-07-26 Verdict — UCCA-TM-2026-07-26-E §4 item 1 (file synthesis v3 over v2) verified DISCHARGED at commit 84250d82, on bytes read over the bridge. Confirms the baton's queue-head item was executed after the baton closed and before the next window opened, and grades it CLEAN — every baton requirement met. §3 reviews and endorses two actions in that commit that were not in the relay: TM-E filed with a current-baton row superseding TM-C via the unfiled TM-D, and TM-C's status cell flipped to SUPERSEDED so exactly one row claims the current baton — noting the commit message disclosed the scope excess, named the cold-start defect it prevented, and cited the house's own precedent (9c40ad0). "The disclosure shape is right: the record states its own scope excess rather than hiding it." §4 records residue found and fixed from that seat: the claude.ai project copy of the synthesis was still v2 and still carried the known-false §5.4 — "the error most likely to be re-propagated by a later reader, sitting in the layer every future cold start reads" — replaced with the filed v3 bytes. The falsehood lived in three places: the repo (fixed at 84250d82), the project (fixed there), and the closed session's memory (expired with it). ISSUED 2026-07-26 (second window). Mints nothing, rules nothing, builds nothing. Substrate snapshot inside is dated — do not assert live from it. sha256 c109698301dffd4ab3fe69c2c1670af83106ceece531bac2f0efbd600bd89b0b ground/UCCA-VERDICT-SYNTHESIS-V3-FILING-2026-07-26.md
UCCA-SHARPENING-TRACED-SEMANTICS-RULING-2026-07-26 Sharpening — the decision structure that produced the v1.2 ruling. DECISION STRUCTURE ONLY; never the source of applied canon text. States the gap from canon bytes (the house ratified a finding's mechanics without ever ratifying what it asserts), poses two candidates — A: TRACED = "this requirement is met" vs B: TRACED = anchored responsiveness with named exclusions — and grades the evidence under the synthesis's own SUPPLIED / BINARY-OFFERED / VOLUNTEERED discipline. Three independent lines converge on B: the house's own filed 2026-07-19 scoping (never ratified, hence forgotten); 4/4 volunteered external corroboration, weighted honestly as corroboration, not authority — four language models share a training distribution and no citation in the set is verified; and the decidability constraint that settles it without any opinion at all — the engine reads documents by construction, satisfaction is not decidable from documents, and "a verdict semantics undecidable from the instrument's input is not a stricter semantics — it is an unimplementable one." §3.5 is the pushback section and states B's costs plainly: the certificate's claim becomes thinner than a buyer of "compliance verdicts" expects; every surface must sell the thinner true thing; the "sounds like grep" objection arrives and must be answered; and B is a demotion of the implied claim that the register should record without flinching. §4 carried the proposed ruling text; §7 the ranked decision points. ISSUED 2026-07-26 (second window) — DRAFT for ruling, recommendation ADOPTED. Its §4 text is the source of the ruled wording as applied through the amendment, not directly; nothing here is canon on its own. sha256 dff15a5774532533933ce447ce4d2fc43d42d6a7f174b1c9208cdaf58c1d6c39 ground/UCCA-SHARPENING-TRACED-SEMANTICS-RULING-2026-07-26.md
UCCA-TM-2026-07-26-E Session-close baton for Sun 26 Jul 2026 (E) — CURRENT SESSION REFERENCE, read first at cold start. The session that opened to file one baton's owed items, obtained four blind readings of the commission it had sent out, cross-tabbed them, and found that the strongest convergences were convergences on the PROMPT rather than on doctrine. §2 — THE FINDING THAT REACHES ABOVE THE SYNTHESIS, and it is a self-indictment: "Claude asserted that DeepSeek's attack on the universality claim was unanswered by house canon, without reading house canon. It was answered a week earlier, by this house." UCCA-TRIUMVIRATE-UNIVERSALITY-TEST-01 (2026-07-19) had already tested the claim against a VET unit, WHS s19 and the EU AI Act and ruled A1-STRONG killed, A1-WEAK surviving — so the house spent a five-model commission rediscovering its own filed finding. The breach was recall and filing discipline, not thinking, against the house's own standing rule: if I've forgotten something the docs cover, point me at the doc rather than re-derive it. What survives of the objection is not nothing: ADR-0002 is not a sufficient answer — moving legal knowledge into the adapter distributes where the non-neutrality lives, it does not make the verdict neutral, and the engine still emits the finding. That makes the cheapest ruling on the list the one deciding whether "universal reasoner" is a true description or a marketing claim — reached independently from the honesty direction and the commercial direction. The unifying diagnosis of the week, stated once: this house has been calibrating an instrument whose reading was never defined — nine corpora, the basis axis, the collinearity correction, the hard-true-positive brief and three pre-registrations, all downstream of an undefined verdict semantics. §4 owed, in cold-start order: (1) file synthesis v3 over v2 — discharged at this commit; (2) RULE: what does TRACED claim? — semantics, not cardinality, 4/4 volunteered that the honest claim is textual responsiveness rather than compliance; (3) then one calibration pass under the new semantics"the loop breaks when something ships, not when the analysis completes"; (4) obligation-level classification (drift-check throat vs adapter first); (5) verdict grammar, blocked by 4; (6) the absent failure modes, now three — wrong actor · assertion-offered-as-provision · NEW: internal defeater / illusory commitment, volunteered unprompted by 2 of 4 and ranked above every mode the commission supplied; (7) verify the citations before any opinion carries weight — NONE are checked, and four Gemini citations are under active suspicion. Nothing minted; Class B mints on build proof. SUPERSEDED 2026-07-26 by UCCA-TM-2026-07-26-F — no longer the current session baton; read TM-F first. Its §4 item 1 verified DISCHARGED at 84250d82 (the correction was already executed when the F-window opened); item 2 RULED and FILED at a3b9ed0 (NORTHSTAR-01 v1.2, the TRACED semantics); item 3 — one calibration pass under the ruled semantics — is now the queue head; items 4–11 carried into TM-F §3. Bytes unedited — still verify to the digest below. · Filed 2026-07-26 as the then-current session baton. Supersedes UCCA-TM-2026-07-26-D (never filed to the repo — no register row exists to flip; its §4 item 1 discharged at 1f6b80f4, item 2 by the synthesis, item 3 re-framed as four rulings, items 5–11 carried). Reconfirm all live state via a fresh read — do NOT assert live from this baton. sha256 be37e1a10db223436e3d6d444a43d897bc1ab14e2f127e6980d733b73bc3ff15 ground/UCCA-TM-2026-07-26-E.md
UCCA-SYNTHESIS-INTERPRETIVE-DOCTRINE-2026-07-26 Synthesis — four blind readings cross-tabbed question by question against the commission that produced them, and the headline is a CORRECTION AGAINST THE HOUSE'S OWN FINDING. Three of the convergences the house was about to bank are convergences on the prompt, not independent replication: commission §2 supplied the four-family obligation taxonomy, §5 supplied six failure modes (so only the ADDITIONS are evidence), and §7 asked "defend or demolish" while presupposing missing states — so the 4/4 demolition is weaker evidence than it reads. Claude had reported the four-family convergence to Tim as independent replication before running that check: an over-claim in the direction that flattered the already-adopted finding, the same failure shape recorded three times in the day's baton. Consequence for the ledger: the obligation-level ontology is NOT confirmed by four independent seats — it is coherent, adopted without objection by four readers who were handed it, and contradicted by none, which is weaker and still worth something. Per-question map (SUPPLIED / VOLUNTEERED / LEADING / BINARY-OFFERED tags on each): the strongest actionable finding is Q3 — rule offered, state demanded, 4/4 and VOLUNTEERED; Q5's signal is the addition two of four made independently; Q8 4/4 on ranks 1 and 2. Set quality is uneven and the row says so: DeepSeek complete and deepest (40 KB, commission prepended verbatim, diff = one trailing blank line); Gemini complete but citations under suspicion and §8 ends mid-table at rank 5, possibly truncated on the section the commission called most valuable; Perplexity did not answer Q4, Q5 or Q7 at all — not thinly, absent, including the Q7 limb that reaches FOUNDATION-01 §2 — answered Q3 in ~200 words against DeepSeek's ~1,200 on the one question the commission said to answer at length, and carries one authority in the whole opinion (s 15AA) with no cases; Grok complete, one surviving unverified citation of its own (Interpretation Act 1978 (UK) s 15A, present in the page images so not converter damage). §6 frames four rulings in dependency order and takes none — first what does TRACED claim? (new; the baton did not anticipate it), then obligation-level classification, then whether the verdict grammar stays two-valued, then the absent failure modes, now three. Rules nothing, mints nothing, builds nothing, registers nothing. Seam 1 stays CLOSED. SYNTHESISED 2026-07-26 (v3) — NOT A RULING. Supersedes no filed document. ✎ v2 (aa3545de5a0ac38c92d97cd554933098f95864dde56b1b263506c91534b96498) was filed at 1f6b80f4 and is SUPERSEDED IN PLACE by v3 at this commit. Reason: v2's §5.4 asserted that the universality objection raised in the DeepSeek opinion was unanswered by house canon — it is answered. UCCA-TRIUMVIRATE-UNIVERSALITY-TEST-01 (2026-07-19) killed A1-strong and paper-validated A1-weak, and UCCA-NORTHSTAR-01 was amended to the surviving reading on 2026-07-24 (v1.1, Class G — §1 restated to the compiled-normal-form reading with the honest-scope line naming the unconsumed instruments, per the amendment record and UCCA-NORTHSTAR-01.md:127). v3 names this the most serious of the three corrections and the only one that is a canon-recall failure rather than an analytical one — the assertion was made WITHOUT READING THE CANON. v3 also corrects a third error: Grok's Q7 position was rounded up in the first pass of the §3.7 table when his named states do not include the one attributed to him (working now shown). The two v2 corrections stand unchanged (prompt-supplied convergence at §2; Grok's standing at §1.3). 1f6b80f4 is NOT rewritten or amended — the record seals outcomes, never process; the superseded digest is recorded here so the v2 bytes remain identifiable. Effective N = 4. sha256 da6cfe6b9adac0ba5fb6e033322bed6dd20e714940c6a69a896d13c9ffa784e0 ground/UCCA-SYNTHESIS-INTERPRETIVE-DOCTRINE-2026-07-26.md
UCCA-CAPTURE-INTERPRETIVE-DOCTRINE-2026-07-26 Capture — the third frame-break of the day, and the one that reaches above the corpus. An independent specialist reading of statutory and regulatory interpretation, commissioned BLIND, overturns a convention the house adopted the same afternoon. Tim's framing: the house had been "calibrating the electron microscope without anyone who understands particle physics." The finding: our convention was circular, and the prior question was never posed — §3 of the hard-true-positives brief was designed with no classification of the level at which an obligation binds (result-state / conduct / system / document), and the rule-credit convention recorded in the probes-bridge-v1 fixture note is WITHDRAWN as circular for state obligations. What it puts in question sits above the corpus: the two-state grammar may be the actual defect (§3.1); verbal match is inverted evidence, which makes the morning's finding worse than it read (§3.2); the bare element is a pointer, not an obligation (§3.3). §5 names two failure modes with zero probes anywhere in nine corpora; §6 reads the eleven-label taxonomy for what it actually turns out to be. Standing, stated so it cannot be over-read: this is scholarship, not authority — one specialist reading, checkable on its face, binding nobody, and it does NOT cure the build brief's §2 SME blocker; it makes a convention defensible rather than invented, which is an upgrade and not a signature. The blind discipline is the pre-registration rule moved to a new object: the question fixed and recorded before the answer is visible. CAPTURED 2026-07-26 — NOT A RULING. Closes nothing, mints nothing, authorises no build. Marks one filed brief design-provisional by register cell only. Three rulings named at §6, all deferred pending the second reading. sha256 581793b56d54ad319a30bd4f0fba84ba08451e098bfab6e12794d42278157772 ground/UCCA-CAPTURE-INTERPRETIVE-DOCTRINE-2026-07-26.md
UCCA-COMMISSION-INTERPRETIVE-DOCTRINE-2026-07-26 The blind commission instrument — the prompt that produced the four opinions, and itself an object of examination in the synthesis. Issued to independent specialist readers with the commissioning party's framework and the earlier opinion deliberately withheld, on the stated ground that a second opinion anchored on the first is not a second opinion. Invites the reader to find the questions themselves malformed — "that is a finding, not a failure to answer." Eight questions; two near-verbatim replication tests (obligation levels; rule-versus-state) and two weighted where divergence was most expected (ex ante standing of documentary assessment; a defend-or-demolish attack on the two-state format). Filed as evidence, not as doctrine — and the synthesis' §7 records what it got wrong for the next one: §2 supplied the four-family taxonomy, §5 supplied six failure modes, and §7 presupposed that missing states exist, so three apparent convergences are partly artefacts of the instrument. Its digest is also what caught the fourth relay defect of the day (see the GLM-5 void row). FILED 2026-07-26 as the instrument of record for the blind commission. sha256 1a74b58ac408aae334f8b9853f48dd8499fc6a2bfd0dc46037e27387040cca59 ground/UCCA-COMMISSION-INTERPRETIVE-DOCTRINE-2026-07-26.md
UCCA-OPINION-DEEPSEEK-INTERPRETIVE-DOCTRINE-2026-07-26 Received opinion — DeepSeek. Complete; the deepest in the set (40 KB) and the only one that self-evidences its own input. The commission prompt is prepended verbatim (diff from the filed instrument = one trailing blank line), so provenance is readable off the bytes rather than attested: sole input was 1a74b58a…. All eight questions answered; ~1,200 words on Q3, the question the commission said to answer at length. Filed verbatim, bytes untouched, as received. FILED 2026-07-26 — received opinion, admitted to the set (1 of 4). Not a ruling, not authority; one model reading. sha256 6ef5972f5193b55ec79f725987743ce9fe621d71a7e554c8929b859b9d7e7396 ground/UCCA-OPINION-DEEPSEEK-INTERPRETIVE-DOCTRINE-2026-07-26.md
UCCA-OPINION-GEMINI-INTERPRETIVE-DOCTRINE-2026-07-26 Received opinion — Gemini. Complete on all eight questions; CITATIONS UNDER SUSPICION, and §8 ends mid-table at rank 5 with no closing text — possible generation truncation on the section the commission called its most valuable. Where Perplexity fails checkability by not citing, this one fails it by citing what may not exist: opposite routes, same result, and the row carries the caveat so the depth is not mistaken for reliability. Filed verbatim, bytes untouched, as received. FILED 2026-07-26 — received opinion, admitted to the set (2 of 4). Not a ruling, not authority; citations unverified. sha256 51ce0d6d662b351194a4c76a6e1aaa06c816e9358afc9a37b49536eea823f0c7 ground/UCCA-OPINION-GEMINI-INTERPRETIVE-DOCTRINE-2026-07-26.md
UCCA-OPINION-GROK-INTERPRETIVE-DOCTRINE-2026-07-26 (.md) Received opinion — Grok. ARTEFACT OF RECORD: the model's own text, supplied by Tim. Complete, carries at full weight. Two forms, one opinion — this .md is the artefact of record; the .pdf (aee2567e…) is the received original. Route recorded because the failure mode recurs: what arrived first was a six-page PDF, producer jsPDF 4.0.0, every page a JPEG, pdftotext extracting zero characters — a picture of an opinion with no bytes to file. Tim then supplied the original emission as text, which verifies against the page images on every point the OCR had broken (Acts Interpretation Act s 13 and s 15AA correct; parens not braces; mis-describing hyphenated; em-dashes intact). The OCR derivative (edfc8124…) is WITHDRAWN — never filed, moved to _to_delete/2026-07-26-superseded/, and must never be cited: a lossy transcription that corrupts citations and manufactures apparent hallucinations. One suspicion survives recovery and is Grok's own, not converter damage: Interpretation Act 1978 (UK) s 15A, present in the page images, unverified. Filed verbatim, bytes untouched. FILED 2026-07-26 — received opinion, admitted to the set (3 of 4). ARTEFACT OF RECORD for Grok; paired with the received-original PDF below. sha256 0107a18ebb0a03d9b0612090a7632ede10ec98cc3761797fef186a271fadb600 ground/UCCA-OPINION-GROK-INTERPRETIVE-DOCTRINE-2026-07-26.md
UCCA-OPINION-GROK-INTERPRETIVE-DOCTRINE-2026-07-26 (.pdf) RECEIVED ORIGINAL of the Grok opinion — six rendered page images, NO TEXT LAYER. Producer jsPDF 4.0.0; every page a JPEG; pdftotext extracts zero characters. Not a second opinion — the same opinion as the .md row above, in the form it was received. Retained as the received original and as the verification source against which the recovered text was checked line by line. The .md is the artefact of record; cite that, not this. Filed byte-untouched (4,531,535 B). FILED 2026-07-26 — received original, evidence only. Not independently citable; pairs with 0107a18e…. sha256 aee2567e831de1014a15e4d436651dd5694438a46800a99a7ddddf9f919292e5 ground/UCCA-OPINION-GROK-INTERPRETIVE-DOCTRINE-2026-07-26.pdf
UCCA-OPINION-PERPLEXITY-INTERPRETIVE-DOCTRINE-2026-07-26 Received opinion — Perplexity. THREE SILENT NON-ANSWERS: Q4, Q5 and Q7 are not addressed at all — not answered thinly, absent — surfaced only by cross-tabbing each opinion against each question rather than reading end to end. Q7's second limb is the one that reaches FOUNDATION-01 §2, and it is silent on it. Answered Q3 in ~200 words against DeepSeek's ~1,200, on the question the commission said to answer at length even if brief elsewhere. Carries one authority in the entire opinion (s 15AA, Acts Interpretation Act 1901) and no cases. Packaging is contaminated and filed verbatim anyway, as received: a Perplexity logo <img>, a leaked relay fragment reading # insert perpexity into the model name, a preamble sentence the commission expressly forbade, and the whole opinion inside a fenced code block. Bytes untouched. FILED 2026-07-26 — received opinion, admitted to the set (4 of 4), with three questions unanswered. Not a ruling, not authority. sha256 7e6d68c17c511b7dc97239650fe2cae38a9c334c94e08a6d2ba7f4bd3e75932f ground/UCCA-OPINION-PERPLEXITY-INTERPRETIVE-DOCTRINE-2026-07-26.md
UCCA-OPINION-GLM5-INTERPRETIVE-DOCTRINE-2026-07-26 VOID — NO SUCH DOCUMENT EXISTS AND NONE IS FILED. The file supplied under the GLM-5 commission slot hashed to 1a74b58ac408aae3… — byte-identical to the commission prompt itself: 84 lines, ending at "Depth over coverage.", zero bytes of opinion. The filename asserted an opinion; the digest said prompt. This was the fourth relay defect of the day and the first caught by the digest check alone — path and digest, both, every time. RULED by Tim in session, 2026-07-26: no re-run. The slot is closed and is not owed. EFFECTIVE N IS FOUR, NOT FIVE. Any document, baton or citation stating "five opinions" is wrong — this row exists so the gap is recorded as a void rather than read as an absence. VOID 2026-07-26 — nothing filed, nothing owed, no re-run (Tim ruled). N = 4. (no path — no document exists)
UCCA-BUILD-BRIEF-HARD-TRUE-POSITIVES-2026-07-26 Author the first calibration suite in which the correct answer can be TRACED without the material restating the obligation — RULED, corpus-by-ADDITION only. Closes the gap at UCCA-NOTE-BASIS-AXIS-COLLINEARITY-2026-07-26 §5: across all nine existing corpora no probe's correct answer is TRACED via a judgement bridge, so the false-negative cell is unconstructable and the engine's under-claim behaviour has never been exercised once. The governing distinction: verbatim → TRACED is a correct semantic entailment and is not being fixed; TRACED → verbatim is the corpus accident and is the only defect addressed. The tuning trap this removes: any change making the engine more conservative improves the score on every probe that exists while degrading the behaviour no probe tests — optimising against today's corpus selects for a quote-matcher and reports it as progress the whole way down (an ADR-0002 drift failure arriving through the measurement layer). Design — minimal pairs: one obligation, -pos/-neg materials differing by the smallest edit that flips the answer, same expected_basis on both sides, so the key asserts "this edit is what makes the difference" — a narrow, reader-auditable claim rather than an abstract judgement. This closes the corpus gap and breaks the collinearity in the same move: each derived label lands on both sides of the key, so expected_basis carries information not derivable from expected for the first time — within this suite only, never retroactively. Shape: 8 derived labels × 2 pairs (32 elements, 16/16) + 3 verbatim controls = 35, one domain held constant, strict-literal, class 2, sme_validated: false, kind: "traced" (PROBE_KINDS is NOT extended — the distinction lives in expected_basis alone). inference-easy/inference-hard added late: the only two labels authored to grade inference difficulty — the hypothesis's own variable — currently sit defence-contrast-v1-only, 100% NOT_YET, in the suite with one post-gate run; including them decollinearises the whole closed vocabulary for two extra pairs. Every element carries a written rationale naming the bridge — the corpus-side half of declared basis, the instrument three filed documents call "the honest one, which does not exist". §2's BLOCKER STANDS UNRESOLVED and is not cured by any ruling: for a hard true positive the key IS the contested judgement — the accountable call FOUNDATION-01 §2 says the engine never makes — and this house has no SME. Minimal pairs make the key auditable, not validated. §2.3 is the weakest thing in the document, and says so: Claude authors and Alex reviews, which bounds the conflict without removing it — the author of the keys is still the seat reading the engine's answers against them, and if the first run flatters the engine, that is the moment to spend an outside review, not to accept the number. Seams: 0 author+review (disagreements filed, not argued; a review that changes nothing is a review that did not happen) · 1 register with shape coverage (§4.2b: nothing today pins a new suite's counts, so "suites green" would pass a half-authored fixture) · 2 promote expected_basis conditionally per set — if a set carries the field on any probe every element must carry a valid one; absence stays legal, so v1/v2 (26 unlabelled elements) pass by design and the existing strip-the-field assertion stays green exactly as written; partial presence becomes illegal · 3 non-collinearity + pair-completeness acceptance tests, both failing loudly · 4 ship (marker bump, poll rollout) · 5 catalogue · 6 first run, measurement rule pre-registered before the first record exists. ✎ Seam-2 pre-flight verified independently at filing: all seven labelled suites are FULLY labelled (aviation 11/11, defence 13/13, defence-contrast 7/7, finance 12/12, finance-dense 35/35, pharma 13/13, hard-demo 5/5); v1 0/11 and v2 0/15 carry no field; zero suites fail the new rule today — a door-close, not a migration, and that basis expires the moment a partial suite exists. RULED (v0.3) 2026-07-26 — Class B, mints on build proof, never on this document. All four §0 questions answered: build it · Claude authors / Alex reviews · eight derived labels at ~35 elements · expected_basis enforcement rides with this brief. THREE are Tim's own rulings; §0.2 (authorship) was ruled by Claude under Tim's delegation, is NOT Tim's personal ruling, and is correctable at any point before Seam 1. Supersedes drafts v0.2 (ab9a3417…) and v0.1 (554f9547…) — neither was ever filed, confirmed at filing time. The suite ships sme_validated: false, may never read "Certified", and every figure it produces is agreement-with-an-author-key until someone qualified signs it. sha256 f4f6f3318d021bff2df3d2a01b7d01f0b451825d849011f4f8e7cd79eced4283 (118 lines; no expected digest accompanied the relay — computed at source before the bytes entered the repo) · DESIGN PROVISIONAL from 2026-07-26 per UCCA-CAPTURE-INTERPRETIVE-DOCTRINE-2026-07-26. The minimal-pair architecture, the non-collinearity and pair-completeness tests, and the Seam 1/2 substrate work all stand. What does not: §3 was designed without any classification of the level at which an obligation binds (result-state / conduct / system / document), and the rule-credit convention recorded in the fixture note is WITHDRAWN as circular for state obligations. The fixture is unregistered, so it is re-authored rather than corrected. Seam 1 stays CLOSED pending three rulings — level classification, verdict grammar, and the two absent failure modes — none of which is to be taken on one reading. Bytes untouched and still verify to f4f6f331…. ground/UCCA-BUILD-BRIEF-HARD-TRUE-POSITIVES-2026-07-26.md
UCCA-NOTE-BASIS-AXIS-COLLINEARITY-2026-07-26 The basis-correlation test's classifying axis was the answer key relabelled — recorded by note and register cell, no filed bytes rewritten. Discharges UCCA-TM-2026-07-26-C §4 item 1. The finding: cross-tabbing expected_basis × expected across the seven domain corpora gives verbatim × NOT_YET = 0, verbatim × TRACED = 27, non-verbatim × TRACED = 0identity, not correlation, holding in each of the seven separately (aviation 3, defence 4, defence-contrast 1, finance 3, finance-dense 12, pharma 4, hard-demo 0), zero unlabelled elements, zero orphan labels. So DIRECT ≡ the expected-TRACED set and DERIVED + NO-TRACE-EXPECTED ≡ the expected-NOT_YET set: the partition measures the key, not the basis. Correction 1 — the View B collapse map is RETIRED AS AN INFERENTIAL INSTRUMENT; its semantic defence was correct and insufficient, because §3 never checked whether the classifier was independent of the outcome. It survives as a description of the vocabulary and may never again partition results. What would have caught it: one cross-tab, costing seconds — and the discipline as practised could not have surfaced it, because a pre-registration protects against choosing the analysis, not against a broken axis (the map was fixed, disclosed, timestamped and filed 33 s ahead of the first artefact). Correction 2 — two readings in the verdict, cell counts undisturbed: "no verbatim element moved" and "no element whose correct answer was TRACED moved" are the same sentence, so the capture's hypothesis was not measured and could not have been at any sample size; and p = 0.0909 is arithmetically correct and refers to nothing of interest — a trustworthy procedure over a collinear axis returns a trustworthy measurement of the wrong thing. Restated on the outcome axis as an enumeration requiring no statistic: expected-TRACED 22 / 22 stably correct, 0 errors, 0 oscillating; expected-NOT_YET (49 less 4 gate-frozen = 45) 34 correct, 7 stable errors, 4 oscillatingevery error a false positive; not one false negative. The seven stable errors are the same failure the Type-A gate suppresses with the marker removed — 21 TRACED emissions, 22 anchors, fence_ok on every one — so fabricated_anchor_rate 0.0 is consistent with this failure rather than reassuring against it; the fence was never the instrument that would catch it, and each probe carries exactly one material section, making it a judgement failure, not a retrieval failure. §5 — THE CONSEQUENCE THAT OUTRANKS THE CORRECTION: a false negative is UNCONSTRUCTABLE from these corpora. No probe anywhere in the nine has expected: TRACED reachable only across a judgement gap; the two general suites' eight expected-TRACED elements are verbatim or near-verbatim restatements (v2's adversarial probes are harder by retrieval noise, not inferential distance). So the under-claim direction has never been exercised, the 22/22 is a statement about trivial cases and must never be quoted as accuracy, "over-claims and never under-claims" is a true description of these records and an untested claim about the engine, and a corpus whose only true positives are quotable rewards a quote-matcher — the ADR-0002 drift failure arriving through the measurement layer. Does not rescue anything: the §3 quarantine stands whole (re-partitioning does not launder it; reasons 1 and 3 untouched, no p-value may be computed on §4); the unvalidated key still reaches 12 of the 22; and the asymmetry is partly designed in — 37 of the 49 expected-NOT_YET elements sit in honesty_tempting probes, so a corpus of over-claim traps with verbatim-gimme positives yields this shape almost regardless of the engine, and any citation dropping that paragraph is a misuse. §7 records a second absence: v1/v2 carry no expected_basis field at all (26 elements) — absent, not empty. §8 proposes two standing rules: cross-tab the classifier against the outcome before partitioning, and establish the field exists in every corpus in scope. ✎ VERIFIED AT FILING on the corpus bytes, independently of the note: the 27/0/0 identity and per-suite breakdown; the §4 denominators (22 expected-TRACED, 49 expected-NOT_YET in the four measurable suites); §6.3's 37 of 49 (aviation 8/8, finance 9/9, pharma 9/9, finance-dense 11/23); and all eight v1/v2 expected-TRACED probes read individually — every one a verbatim or near-verbatim restatement. ISSUED 2026-07-26. Discharges UCCA-TM-2026-07-26-C §4 item 1. UCCA-NOTE-BASIS-CORRELATION-PREREGISTRATION-2026-07-26 §3's View B collapse is RETIRED AS AN INFERENTIAL INSTRUMENT — readable as a description of the vocabulary, never again used to partition results. UCCA-VERDICT-BASIS-CORRELATION-2026-07-26 §1's DIRECT zero and §4's second bullet are CORRECTED IN READING, not in fact — the cell counts stand exactly as reported and mean less than they were taken to mean. The §3 quarantine is NOT lifted and this note does not weaken it. Nothing minted. No expected digest accompanied the relay; sha256 computed at source before the bytes entered the repo: fe5a95c561f9940ef9fc3a0f890bc9b696665a4b55ec6f17000911373d0367ef (144 lines) ground/UCCA-NOTE-BASIS-AXIS-COLLINEARITY-2026-07-26.md
UCCA-TM-2026-07-26-C Session-close baton for Sun 26 Jul 2026 (C) — CURRENT SESSION REFERENCE, read first at cold start. "The session that pre-registered a test, got the null it predicted, and then found — in the last read before close — that the test was incapable of measuring what it named." Arc: cold start corrected on substrate not memory (TM-B's "file the verdict" was already discharged) → corpora read before the test was designed and changed it (eleven labels, two incompatible axes, unenforced, one vocabulary test on the zero-information suite) → third pre-registration filed c27571e 15:53:56 with the window's uncleanliness disclosed, register cell aligned 0450713, first measurement artefact 33 s later → the measurement returned the pre-named row (DIRECT 0/22, DERIVED 3/19, p = 0.0909), verdict 2fddb99, NO CLASS MINTS → the completeness answer landed and was the good one (no oscillator outside the Type-A verdict's five; its variance enumeration was complete) → the correctness column quarantined on three grounds and stayed quarantined after the breakdown discharged one (b3f4113) → "silence" corrected by record to stable over-claim → §3.3 returned the worse branch: 21 TRACED emissions, 22 anchors, fence_ok on every one, every reason null, zero missing findings. §2 — THE COLLINEARITY FINDING, which outranks everything else in the session and undercuts the author's own design: cross-tabulating expected_basis against expected across the seven domain corpora gives verbatim × TRACED = 27, verbatim × NOT_YET = 0, non-verbatim × TRACED = 0identity, not correlation. So the pre-registered DIRECT/DERIVED axis is the TRACED/NOT_YET answer-key axis relabelled; "no verbatim element oscillated" and "the engine never errs when the correct answer is yes" are the same sentence and no reading of these records can separate them. The map was fixed on the vocabulary's semantics and the cross-tab against expected was never checked. Restated on the outcome axis, where the confound does not exist and no statistics are needed — an enumeration, not a test: expected-TRACED 22/22 stably correct, 0 errors, 0 oscillating; expected-NOT_YET (45 usable, 4 gate-frozen excluded) 34 correct, 7 stable errors, 4 oscillating. EVERY error is a false positive; there are NO false negatives. And the connection that makes it the session's real result: the Type-A gate proved live this morning is a false-positive suppressor for the marker-carrying case — these seven are the same failure with anchors that carry no marker, so fabricated_anchor_rate 0.0 is consistent rather than reassuring; the fence was never the instrument that would catch this, and the gate is a narrow detectable instance of a general failure that is currently invisible. All seven probes carry exactly one material section, so "every anchor cites S1" is vacuous and the failure is judgement, not retrieval. New landmines: a classifying field can be a relabelling of the answer key — check the cross-tab before partitioning, every time; the fence is not an over-claim detector and must never be cited as one. Ledger: a pre-registration protects against choosing the analysis, not against a broken axis — the missing check cost seconds; pre-observed is not pre-registered and is not worthless either; quarantine discipline held under favourable results; a verdict's null is worth filing (it closed an item, blocked a brief, and saved building moderation on an unmeasured premise). ✎ §2 INDEPENDENTLY RE-VERIFIED at filing time on the corpora: 27 / 0 / 0 confirmed, identity holds in each of the seven separately, zero unlabelled elements. One precision added: the general suites v1 and v2 carry no expected_basis field at all (26 elements) — they were never in the measurable set, but any future partition must exclude them explicitly, because the field is absent, not empty. SUPERSEDED 2026-07-26 by UCCA-TM-2026-07-26-E (via the unfiled TM-D) — no longer the current session baton; read TM-E first. Its §4 item 1 (the collinearity correction) was discharged at f64fec3. Bytes unedited — still verify to the digest below. · Filed 2026-07-26 as the then-current session baton. Supersedes UCCA-TM-2026-07-26-B (its §4 item 1 confirmed already discharged; item 2 CLOSED by UCCA-VERDICT-BASIS-CORRELATION-2026-07-26). Carries the collinearity finding at §2 — verbatim is EXACTLY the expected-TRACED set in all seven corpora, so the pre-registered DIRECT/DERIVED axis was collinear with the answer key — and the restated result on the outcome axis: 22/22 expected-TRACED correct, all 11 errors on expected-NOT_YET, 22 fence-passing anchors under 21 wrong TRACEDs. §4 item 1 is to file that correction; nothing starts before it. Reconfirm all live state via a fresh read. sha256 3dd71984586deb772b937627631dace7035f35976cac682ce9986b613218a11c ground/UCCA-TM-2026-07-26-C.md
UCCA-NOTE-BASIS-BREAKDOWN-AND-QUARANTINE-2026-07-26 Discharges §6 item 1 of the basis-correlation verdict — and the breakdown returns the opposite of what that verdict anticipated. §3 reason 2 of the verdict made a conditional: if the stable-and-wrong DERIVED elements concentrate in finance-dense-v1, then "derived bases are silently wrong" and "finance-dense's unvalidated key disagrees with the engine" are the same sentence. They do not concentrate there — the split is 3/3, and the only DERIVED label present outside that suite, plain inference, runs 3 of 6 wrong across pharma-v1 and finance-v1, both class-1 suites, with both pharma cells wrong. So the correctness column clears the cross-suite bar the oscillation column failed, and the unvalidated-key confound does not reach half the effect. The six verified against corpus bytes: pha-infer-qualification / pha-infer-sterility / fin-infer-validated (inference, honesty_tempting), fin-bestex-fee-latency-multihop (inference-multihop, honesty_tempting), fin-bestex-retail-scope (scope, not_yet), fin-aml-cdd-uptodate-cycle (temporal, not_yet); per-label reconciliation closes on 10/6/3 without residue, and scope is 0 for 2 — neither element both stable and correct. THE NEW FACT — "silence" is the wrong word, corrected by record: all six carry expected: NOT_YET; there are ZERO under-claims in the set, and four of six are kind: honesty_tempting — probes authored to tempt an over-claim, which the engine fails stably, three runs each. The failure is stable over-claim in the certification-supporting direction — the phrase the attribution-and-stopping note already used about a different element while calling it "the dangerous one". Worse than oscillation because an oscillating element advertises its own contestability while a stably over-claiming one returns the same confident TRACED with an anchor and looks exactly like a correct trace. A third correction, made by the author against their own quarantine: reason 1 is weakened, not untouched — the capture (filed 2876a6a, before the pre-registration existed) already named pharma's and finance's inference probes as stably wrong, so the observation was pre-observed in a filed document, naming the right suites and basis class. Pre-observed is not pre-registered: the statistic, population, exclusions and decision rule were all fixed after the data existed. The correct sentence is "a strong candidate hypothesis with a filed prior observation and no valid test yet" — neither "post-hoc, therefore worthless" nor "survived scrutiny, therefore admissible". §6 constrains the next instrument (not a brief): not oscillation (every element here is perfectly stable); not symmetric wrongness (the finding is directional — zero under-claims); not finance-dense alone and not excluding it; moderation is not it at any N — running a stably over-claiming element three times returns the same over-claim and reports "the engine agrees with itself", which is worse than saying nothing; the honest instrument remains declared basis, which does not exist. Also records relay hygiene (§5.3): echo doc_id and final line both directions, every time. ISSUED 2026-07-26. Discharges UCCA-VERDICT-BASIS-CORRELATION-2026-07-26 §6 item 1. Its §3 QUARANTINE STANDS UNCHANGED — reason 2's factual premise settled favourably, reasons 1 and 3 untouched and either alone sufficient. Lifts nothing, unblocks nothing, mints nothing, authorises no build/run/schema/probe change; edits no filed bytes. Claims no rate for over-claim on client material — six elements on synthetic corpora is a direction, not a rate. §3.3 owed back before §3 of this note is load-bearing. sha256 977f1aad93d5a4c6633586582e6405d6bc24d5092bc1abdf7553da7e934ca2ff ground/UCCA-NOTE-BASIS-BREAKDOWN-AND-QUARANTINE-2026-07-26.md
UCCA-VERDICT-BASIS-CORRELATION-2026-07-26 The basis-correlation test returns the null it was pre-registered to return — MINTS NOTHING. Closes UCCA-TM-2026-07-26-B §4 item 2 on the pre-registered test only, under the collapse map, exclusions and outcome table fixed at c27571e before any record was joined to expected_basis. Result: DIRECT 0/22, DERIVED 3/19, NO-TRACE 1/26 — one-sided Fisher p = 0.0909, which is row 2 of the pre-registration's own §6 table, named there in advance as "the cell the disclosure at §5 predicts" and as licensing nothing at 0.05. The capture's §4 hypothesis is NOT confirmed — directionally consistent (every oscillator on the basis axis is DERIVED; no verbatim element moved in eleven usable runs) and one oscillator short of its own bar. Directionally consistent is not proven, and the pre-registration exists so that difference cannot be smoothed over in the writing. Moderation gets no brief — the block was never conditional on a favourable direction, only on the result read against §6, and read against §6 this does not lift it. The confound stands unresolvable in this dataset: 2 of 3 DERIVED oscillators sit in finance-dense-v1, which holds 13 of 19 DERIVED elements; the entire cross-suite check is six elements carrying one oscillator between them. THE RESULT ACTUALLY WORTH HAVING — no oscillator exists outside the Type-A verdict's five, so UCCA-VERDICT-TYPE-A-GATE-2026-07-26 §1's variance enumeration was COMPLETE; that was an open question when it was filed and could not be claimed from its own reads. A quieter second confirmation: anchor churn under a stable state on six elements, four of them verbatim — so a verbatim element can re-quote differently while holding its state, which is why the DIRECT zero is a statement about state, not determinism, and why defence-contrast-v1's byte-identical return was never the strong evidence it briefly looked like. §3 (the correctness column: DIRECT 22/0/0, DERIVED 10/6/3, NO-TRACE 24/1/1) IS QUARANTINED on three independent grounds, any one sufficient: post-hoc (the pre-registration declared one test — oscillation — and named confident error only as a limit no sample size could resolve; naming a blind spot is not pre-registering a test on it); under-reported against §7.7's every-cell requirement and §3's cross-suite bar; and its p-values (0.006, 0.0003) are void as evidence — recorded in the verdict only so nobody recomputes them and believes they have found something. Disposition, both halves travelling together: the most promising direction on the table, with exactly zero evidential standing today. §6 item 1 — the named breakdown — is OWED before §3 may be cited by anyone, including its own author. Also records a process defect owned by the author: a relay carried docs HEAD as a bare fact that was stale ten minutes later, while the very note it relayed instructed pinning to declared versions and never HEAD — a relay states HEAD as a timestamped observation or not at all. Stopping rule satisfied: no suite partially measured. ISSUED 2026-07-26 — NO CLASS MINTS. Pre-registered test returns p = 0.0909; the §4 hypothesis is NOT confirmed and moderation remains blocked. Establishes that UCCA-VERDICT-TYPE-A-GATE-2026-07-26 §1's variance enumeration was COMPLETE. §3 (the correctness column) is QUARANTINED — post-hoc, under-reported, void as evidence — and may not be cited, summarised, or carried into a baton except as quarantined. §6 item 1 is owed before it may be cited at all. · §6 item 1 DISCHARGED 2026-07-26 by UCCA-NOTE-BASIS-BREAKDOWN-AND-QUARANTINE-2026-07-26 — the six do NOT concentrate in finance-dense-v1 (3/3 split; inference 3/6 wrong across pharma and finance), so reason 2's premise is settled in the favourable direction and the cross-suite bar is cleared. §3's 'silence' characterisation is CORRECTED there to stable over-claim. The quarantine STANDS on reasons 1 and 3. · §1 and §4 CORRECTED IN READING 2026-07-26 by UCCA-NOTE-BASIS-AXIS-COLLINEARITY-2026-07-26 — cell counts stand, meaning reduced. The classifying axis was collinear with the answer key, so "no verbatim element moved" and "no element whose correct answer was TRACED moved" are the same sentence; the capture's hypothesis was not measured by this test and could not have been at any sample size. p = 0.0909 is arithmetically correct and refers to nothing of interest. The result restates on the outcome axis as an enumeration requiring no statistic: expected-TRACED 22/22 stably correct, 0 errors, 0 oscillating; expected-NOT_YET (45 usable) 34 correct, 7 stable errors, 4 oscillating — every error a false positive, no false negatives, and no false negative constructable from these corpora. §3's QUARANTINE IS NOT LIFTED — the enumeration re-partitions the same quarantined column and inherits reasons 1 and 3 in full. Bytes untouched and still verify to 91e20d55…. sha256 91e20d55583b06e3c20038de2201ae305295dc85fe87ea6a23f9f3d1000569d1 ground/UCCA-VERDICT-BASIS-CORRELATION-2026-07-26.md
UCCA-NOTE-BASIS-CORRELATION-PREREGISTRATION-2026-07-26 THIRD pre-registration — the basis-correlation test fixed before any record is joined to a basis label. Prerequisite to UCCA-TM-2026-07-26-B §4 item 2. "Free is not neutral": the test has three choosable-after-the-fact design choices (which labels group, which elements are excluded, what counts as a result), so the map is fixed while unjoined. Substrate finding that changes the test — machine-derived from the corpora this session: expected_basis is real and per-element (keyed by element_ref, exact join on (probe_id, element_ref)), but it is eleven labels, not four, drifted silently; nothing enforces the vocabulary — no loader, validator, reasoner or scorer reads it, and its one test (test_benchmark_suites.py) asserts a four-label closed set against defence-v1 alone, a suite contributing zero oscillation information; and two labels are not on the hypothesis's axis at all (not_yet/ungrounded describe the expected outcome, not the basis — 30 of 71 measurable elements, 42%). Only 4 of 6 run suites can measure oscillation (≥2 post-gate runs): defence-v1 and defence-contrast-v1 contribute nothing, including every inference-easy/inference-hard element — the only labels authored to grade inference difficulty, the hypothesis's own variable. The suite built to answer the question is the one that was run once. Fixed map: View A (every label × every suite, numerator and denominator, no pooling) is primary and exists so the grouping can be rebuilt by any reader; View B is the only collapse authorised for a headline — DIRECT (verbatim, 22) / DERIVED (inference, inference-multihop, temporal, scope, term-drift, partial, 19) / NO-TRACE-EXPECTED (not_yet, ungrounded, 30). Stated confound: three DERIVED labels are finance-dense-only and finance-dense is the noisiest suite, so "derived bases oscillate" and "finance-dense oscillates" are the same sentence in this dataset and cannot be separated by it; outside finance-dense, DERIVED is six elements, all plain inference. Mandatory exclusions: baselines never enter oscillation (two-column separation inherited in force); the four gate elements excluded by name because a gate-acted element is deterministically frozen and counting it stable would report the gate's determinism as a reasoner property; and the exclusion cannot be completed — no gate-action field exists, so any unlisted gate-acted element is frozen and uncounted and every rate is biased toward stability by an unknown amount (direction known, size unrecoverable). DISCLOSURE — the window is not clean, and the note says so rather than claiming otherwise: four oscillators were already visible in the filed verdict when the map was fixed — three in DERIVED (avi-infer-dal inference, fin-algo-selfassessment-gap temporal, fin-algo-pretrade-fixedincome-scope scope), one in NO-TRACE-EXPECTED, none in DIRECT — i.e. the hypothesis's direction was known to the author of the grouping, and the adversarial reading (that temporal/scope were placed in DERIVED because they carry known oscillators) cannot be refuted from inside the document; View A is what keeps the regrouping available. The test may already be over: if the read returns exactly these movers it discovers no new oscillator, and its whole marginal contribution is denominators, the completeness check on the verdict's variance list, and whether any verbatim element moved. Outcomes pre-declared (one-sided Fisher, hypothetical cells): 0/22 vs 3/19 → p=0.091, the outcome the disclosure predicts, and it licenses NOTHING at 0.05; 4/19 → 0.038 licenses only a narrow one-suite claim; ≥2 DIRECT oscillators falsifies the hypothesis as stated and the N× moderation cost case becomes the real one. The standing limit no sample size fixes: this measures movement only — a class can score 0% oscillation and be wrong every run, and nothing here distinguishes "stable and right" from "stable and wrong". Also records two corrections, bytes unrewritten: the verdict's "instance nobody authored" wording outruns the corpus — row 4 carries expected_basis: ungrounded and expected: NOT_YET, so its author did expect it untraceable; the precise claim is that it is not an authored marker trap (kind: not_yet vs rows 1–3's honesty_tempting), which tightens the finding rather than retracting it; and the vocabulary test is load-bearing for a claim it does not check. PRE-REGISTERED 2026-07-26 (third issue) — fixes the collapse map, the exclusions and the outcome table for the basis-correlation test BEFORE any record is joined to expected_basis. Discloses at §5 that four oscillators were already visible in the filed verdict. Records two corrections at §8, neither rewritten. · Ordering evidenced, not asserted: filed at c27571e (committed 2026-07-26 15:53:56 +1000); the measurement's first artefact was created 15:54:29 +1000 — 33 s later. Worthless if filed after the measurement returns, and to be withdrawn rather than back-dated. Authorises no build, no run, no corpus/test/probe change; does not unblock the moderation brief — which stays blocked on the result read against §6, and per §6 the most likely result does not unblock it. sha256 0cc0c08220887bddc2dca6d3b0c5288ac8925adb6946dbcd0dd8d184e3408067 (171 lines; no expected digest was supplied with the original relay — this value was computed at source before the bytes entered the repo, and the later relay's stated digest matches it) · §3's View B collapse map is RETIRED AS AN INFERENTIAL INSTRUMENT 2026-07-26 by UCCA-NOTE-BASIS-AXIS-COLLINEARITY-2026-07-26expected_basis: verbatim is EXACTLY the expected: TRACED set across all seven domain corpora (27 / 0 / 0; identity in each of the seven separately), so DIRECT/DERIVED is the answer-key axis relabelled and any partition by it measures the key, not the basis. The map stands as a description of the vocabulary; it may never again be used to partition results. §5's disclosure and §6's outcome table are unaffected in fact and reduced in meaning by that amount. Bytes untouched and still verify to 0cc0c082…. ground/UCCA-NOTE-BASIS-CORRELATION-PREREGISTRATION-2026-07-26.md
UCCA-TM-2026-07-26-B Session-close baton for Sun 26 Jul 2026 — CURRENT SESSION REFERENCE (read first at cold start). "The session the gate was proven and the engine was caught being unreliable in the same afternoon. One of those was the plan." Arc: both Type-A documents filed byte-verbatim (c37d2e3, closing the dead-citation gap under the four gate seams) → the amendment ruled by register cell, not by rewriting the artefact (30e11ed, 1 file +1/−1 — filed bytes are never edited to record a ruling; precedent worth keeping) → first pre-registration (8ca1728) → thirteen sealed records in ~80 minutes across six suites, Tim triggering every one → a determinism claim falsified inside one run → capture filed (2876a6a) → an outside review commissioned by Tim, from a party with no stake, which found the error that mattered (the replacement attribution rule had been deferred to the verdict, i.e. would have been written with the answer visible) → second pre-registration (8bd9a34) before the bytes were opened, window held → run-lock built/tested/deployed (1d32d69 docs · 2badc53 surfaces · deploy ec7604c7) → twenty records read, verdict issued, Class B minted on the bounded claim. Engine byte-unchanged all session (c5ba1e8); surfaces-only substrate change; synthetic probes only; no fence crossing. Carries the ledger points that must not be lost: the counterfeit signature (fin-algo-selfassessment-gap produced the gate's exact apparent shape on a marker-free quote then reverted — a gate action cannot revert; had the naive "did it flip the right way" test shipped, that element would have been logged as gate-attributed and the proof would have been quietly wrong); stability does not imply correctness — everything built this week detects movement, nothing detects confident error, and the data has it; the record seals outcomes, never process (three times in one day the ledger wanted a field that isn't there — token counts, gate version, gate action); the permanent measurement loss. New landmines: /calibrate has NO single-flight at the route (apps/admin-api/src/index.ts:95, inline above the GET-only guard — no lock, no in-flight check, no dedupe; U2 made the surface single-flight, the route is still open; the container's startCalibration is UNREAD); a test can encode a defect as a contract (the pre-existing assertion "Run re-arms immediately after POST" was the defect — flipped and flagged loudly, never silently inverted); small samples were over-read three times in one day → standing correction, the title may not outrun the body; never defer a rule to the moment it adjudicates — a rule that governs bytes is filed before the bytes are opened or it is worthless. ✎ ALREADY DISCHARGED AT FILING TIME: this baton's §3 says "the verdict is NOT in the repo" and its §4 item 1 says "file the verdict" — both were true when it was authored and are superseded by fact: UCCA-VERDICT-TYPE-A-GATE-2026-07-26 was filed at d529931 with the register row and status as specified. A cold-start reader must NOT re-file it. Baton bytes stand unedited; the correction lives here, per the same register-cell discipline the baton itself records. Next open item is therefore §4 item 2 — the basis-correlation test, free, on records that already exist, and moderation gets no brief until it returns. SUPERSEDED 2026-07-26 by UCCA-TM-2026-07-26-C — no longer the current session baton; read TM-C first. Its §4 item 1 was already discharged at its own filing time (verdict filed d529931) and item 2 is CLOSED by UCCA-VERDICT-BASIS-CORRELATION-2026-07-26; items 3–10 are carried and re-ranked in TM-C. Bytes unedited — still verify to the digest below. · Filed 2026-07-26 as the then-current session baton. Supersedes UCCA-TM-2026-07-26, which was never filed to the repo — no register row exists to flip, and nothing cites it but this row and the run-lock brief. Does not supersede UCCA-TM-2026-07-24-B-TECH (still the current tech reference; this is a session baton and makes no claim on it). Reconfirm all live state via a fresh read — do NOT assert live from this baton. sha256 972366844a844d60f58a4a6e9117014c4aee08e473ebb61ca672637166d5e762 ground/UCCA-TM-2026-07-26-B.md
UCCA-VERDICT-TYPE-A-GATE-2026-07-26 The Type-A insufficiency gate fires live — MINTED Class B on a BOUNDED claim. Closes exit criterion 4 of UCCA-BUILD-BRIEF-TYPE-A-INSUFFICIENCY-GATE-2026-07-25, issued under the attribution and stopping rules pre-registered at 8bd9a34 before the governed bytes were opened. The claim, and it does not widen — now or in any future citation: the not_reproduced marker is proven live in the running container, NOT "the gate is proven". Finding: four elements across four suites satisfied all three attribution limbs on 11 of 11 opportunities — avi-ungrounded-tcds E1 (2/2), pha-ungrounded-spec E1 (3/3), fin-ungrounded-suitability E1 (3/3), and fin-aml-riskrating-annex E1 (3/3) — marker matching done by importing the engine's own _marker_hits, not reimplementing it. Fabricated-anchor 0.0 on all twenty records. Zero gate-attributable collateral; five variance elements counted and named, never netted off (avi-infer-dal, fin-algo-selfassessment-gap, fin-algo-pretrade-fixedincome-scope, fin-aml-cdd-uptodate-cycle, fin-mrm-documentation-multilimb E4). Row 4 — the instance nobody authored: fin-aml-riskrating-annex flipped 3/3, reported as frequency and not resolved by majority; the gate catches this failure in the wild, not only on its own traps. One precision the mint must never blur: the flip is observable independently of the key; whether NOT_YET was the correct disposition there is a key judgement and finance-dense-v1 is sme_validated: false — so "fires in the wild" is proven, "was right in the wild" is not. The most important negative result: fin-algo-selfassessment-gap produced the gate's exact apparent signature (TRACED→NOT_YET, anchors→0) with an anchor carrying no marker, then reverted — a gate action cannot revert. The reasoner can spontaneously produce the gate's signature, so signature alone never proves gate action; what distinguishes the four is consistency (11/11) against a confounder that reverted 2 of 3, and that remains an inference. THREE LIMITS RIDE WITH THE MINT, UNDISCHARGED: (1) eight of nine markers unexercised — not_reproduced is the only marker appearing in any material section across all nine corpora; (2) the all-anchors guard has ZERO live exercise — all four gate elements carried exactly one anchor, row 4 included, so the mixed-anchor branch never occurred and is proven offline only; (3) gate action is inferred, not observed — the sealed record carries no pre-gate state and no gate-action field, so limb 2 is evaluated against the baseline's anchors as a proxy. Permanent measurement loss (pre-registration §4): post-gate, on any element whose anchors all carry a marker, suite aggregates can no longer evidence whether the reasoner improved or regressed — a steady score no longer implies a steady reasoner. Stopping rule applied: aviation-v1 is reported as a two-run distribution (0.9091, 1.0) that disagrees with itself — never as 100%; n=1 for defence-v1/defence-contrast-v1, n=3 for pharma/finance/finance-dense; finance-dense-v1 accuracy remains agreement-with-an-unvalidated-key and must never be cited as engine performance. Owed, not blocking: fin-aml-cdd-uptodate-cycle E1 shifted NOT_YET→TRACED and held across all three runs where every other variance element flickers — either the v30→v32 bump touched reasoning (contradicting the standing reasoning-neutral assumption for the class-ladder registry) or the single baseline run was the outlier; one baseline sample cannot separate them, and two more finance-dense-v1 runs would answer it. Also owed: whether startCalibration serialises in the container; SME validation of the class-2/3 keys. MINTED (Class B) 2026-07-26 — bounded to not_reproduced; three limits undischarged; aviation reported as a two-run distribution, never as 100%. sha256 dd997c0aab3158500908cf7d47e9f4bd8ccd3c57e07f70c81141f5603ceb9fd3 ground/UCCA-VERDICT-TYPE-A-GATE-2026-07-26.md
UCCA-NOTE-ATTRIBUTION-AND-STOPPING-RULE-2026-07-26 SECOND pre-registration — filed in the gap BEFORE the owed per-element reads arrived, because a rule written after the bytes are visible is a rule written with the answer in hand. The first pre-registration's §3 read defence-contrast-v1's identical return as a zero variance floor and §6 hung "nothing else moves" on it; that floor collapsed the same afternoon, and deferring the replacement to the verdict was itself the error — the verdict issues on the very bytes the rule adjudicates. The attribution rule (binding): a change attributes to the gate iff all three hold — a TRACED → NOT_YET_TRACED transition, on an element whose every pre-gate anchor matched a marker, with anchors dropped to zero. The gate is monotonic and one-directional: it cannot raise a state, add an anchor, or act on an element carrying one substantive anchor. Every other movement is variance — counted and reported per element, never excused, never netted off; a verdict reporting only gate-attributed changes and passing over the rest in silence is defective however favourable the arithmetic. Two columns kept separate and never merged: vs the 24 Jul baseline (confounds gate + v30→v32 delta + run-to-run variance; attributes nothing on its own) and across the three 26 Jul runs of the same suite (same version, same input — the only clean variance measurement). The stopping rule: thirteen runs in ~80 minutes under an improvised stopping rule, with aviation run twice post-gate and stopped on the correct one — so the verdict cites the distribution across every sealed post-gate record for a suite, or it cites nothing; no last-run, no best-run figures; where runs disagree the disagreement IS the result, reported as a frequency, and any suite not fully sealed-and-read is reported as partially measured with the count stated. The masking consequence, now permanent and bound into the mint text: post-gate, on any element whose anchors all carry a marker, the aggregate can no longer evidence whether the reasoner improved or regressed — the gate produces the correct answer either way. Intended behaviour of a deterministic floor, but a standing loss of measurement the mint must state rather than let readers infer a steady score means a steady reasoner. Row 4 is retired as a two-branch question: anchor selection varies run to run, so a non-flip proves nothing about absence and a single flip nothing about typicality — reported as a per-run frequency across all three post-gate records or as unsettled, and never resolved by a majority of three (the same vote-to-resolve error forbidden for moderation). Corrections recorded, not rewritten: the capture's title outruns its body ("concentrated" rests on one element examined at element level with the largest swing admitted unlocated; "rather than a defect" is a favourable name for a stochastic move into TRACED on a Level-A avionics trap — an over-claim in the certification-supporting direction), and its two incompatible readings of avi-infer-dal (scored against the key while argued contestable) must be resolved one way by the verdict, which says which. Author's declared conflict: the same author wrote every document this note corrects and will write the verdict it constrains — that is the conflict it exists to bind in advance. Grants nothing; narrows only. PRE-REGISTERED 2026-07-26 (second issue) — filed before the governed bytes were read; its value is entirely its timestamp, and by its own terms it is worthless if filed after the reads land and must be withdrawn rather than back-dated. Amends no filed document's bytes; authorises no build; does not touch the bounded mint sentence. sha256 c3494895754debe97a6895cec72b5c62bb424c630f7ef447e0e049caa43581f2 ground/UCCA-NOTE-ATTRIBUTION-AND-STOPPING-RULE-2026-07-26.md
UCCA-BUILD-BRIEF-CALIBRATION-RUN-LOCK-2026-07-26 Calibration console run-lock + console honesty — SURFACE-ONLY, three defects in one component. Discharges UCCA-TM-2026-07-26 §4 item 8, carried open across four batons as a UI nicety; it stopped being one when the console took thirteen runs in ~80 minutes for the Type-A proof. U1 — the in-flight banner is derived from the live dropdown (selected, line 91) and rendered at lines 180/357, while the POST sends probe_set_version: suite at click time and nothing stores what was posted; change the dropdown mid-run and the banner silently re-labels the running job. Fix: capture runningSuite at trigger time, render both banners from it, keep suiteLabel so the honest-label rule applies to the banner too. U2 — the selector disables only on trigger.s === "posting" (milliseconds) and line 119 deliberately re-arms Run, so for the whole sealing window concurrent /calibrate is two clicks away; second-order, pendingSince is a single scalar so under concurrency one run's seal can clear another run's banner and the indicator goes dark. Fix: gate both on running, keeping the deliberate-confirm step — a lock beside it, not instead of it. U3 — the fence panel omits the insufficiency_gate block the reasoner publishes to ucca-fence-def KV, on the one panel whose stated job is to show what the engine does; this cost real time when the missing block read as evidence the gate was not deployed. Fix: render it defensively (must not break against an older engine), with the annotation visibly not a marker per UCCA-AMENDMENT-TYPE-A-GATE-CONTROL-2026-07-25 §4.2. Closes the surface half of the Type-A brief's exit criterion 5. The sealed ledger was never at risk — every record self-describes with its own probe_set_version/measured_at; the exposure is entirely at the operator's seat. §5 is REPORT-ONLY and must NOT be built: the /v1/engine/calibration/run handler was not read, so its single-flight behaviour is not briefed — Alex reports where it lives, whether it enforces single-flight, and what a second POST does mid-run; a brief issues after the report. Do NOT touch the honest-label rule, the class ladder, or DEFAULT_SUITE. Sequencing (binding, from the brief): the owed per-element calibration reads on pharma-v1 / finance-v1 / finance-dense-v1 / defence-v1 / aviation-v1 (04:02:45) come FIRST — they block the Type-A Class-B mint; this brief does not. RULED (Tim, 2026-07-26) — as drafted, no changes. Surface-only; U1–U3 to build, §5 REPORT-ONLY. Class B pre-proof; proof for U1/U2 is Tim's operator confirmation on the live console during a real run. sha256 5d37691776e9047b7a2c3589abefe06cdc1e4c7f754e6a7cf493e48841d178c1 · ✎ EXIT CRITERION 6 DISCHARGED 2026-07-27 — operator confirmation on the live console during the calibration pass: the banner named the posted suite mid-seal, the Run control was withdrawn while running, and the fence panel rendered the gate block. Tim's word, verbatim: "all worked find from the ui perspective." Recorded in UCCA-TM-2026-07-27-B. ground/UCCA-BUILD-BRIEF-CALIBRATION-RUN-LOCK-2026-07-26.md
UCCA-CAPTURE-MODERATION-AND-INSTABILITY-2026-07-26 CAPTURE ONLY — a direction and the measurement that provoked it. NOTHING RULED, NO BUILD AUTHORISED. Provoked by the Type-A live run: avi-infer-dal E1 returned three different-in-kind results on byte-identical input at temp 0 (correct v30 → incorrect v32 → correct v32 ~36 min later); the gate cannot have caused it (monotonic toward NOT_YET and drops anchors; this gained one and moved the other way) — the reasoner changed its own mind on an authored judgement trap (developed under a DAL-A process vs verified). §3 proposes moderation: run a contested element more than once, and if the runs disagree report the disagreement as a finding — mechanism in the throat (neutral: "run N, compare, escalate"), policy in the adapter (N, what counts as disagreement, when engaged), a dial beside the strictness dial. §5 is the binding rule if it is ever built: the engine must never resolve the disagreement — majority vote is the engine signing (FOUNDATION-01 §2), and a confidence score is a verdict wearing a percentage. §4 IS A HYPOTHESIS, NOT A FINDING — carried here as such: "findings whose basis is inference oscillate; findings whose basis is verbatim do not." It has NOT been tested. Today's data is consistent with it and does not establish it — pharma's and finance's inference probes were stably wrong across three runs each, a third state (confident error) the hypothesis does not account for and which moderation is blind to. The named cheap test (classify sealed elements by expected_basis, measure oscillation rate by class) is unrun; the whole economic case turns on it (targeted re-runs vs N× across the board). Do not brief a build off this document until that test returns. Also records: a correction to UCCA-NOTE-RUN-PREREGISTRATION-2026-07-26 §3 — seven identical defence-contrast-v1 elements did NOT license a zero variance floor, so §6's "nothing else moves" pass condition is not usable as written (the note is NOT reissued; the replacement reading belongs in the run verdict); and a logging survey (D1 jobs/cognitive_cost exist and are insert-only, but findings are not in D1 at all — no per-element row anywhere, so "which elements oscillate" is unanswerable at client volume; any future findings index is an index, never a source of truth, and must NOT hang off the Compliance surface, which keeps platform certifications and supported frameworks strictly separate). Fabricated-anchor 0.0 on every run. Provenance split deliberately: §2's accuracy figures are Tim-screenshot console aggregates, NOT byte-reads; per-element reads for pharma/finance/finance-dense/defence were owed and unreceived at time of writing. CAPTURED 2026-07-26 — for Tim. Nothing ruled; no build, schema change, table, surface or probe-set change authorised. §4 is a HYPOTHESIS with an unrun test, not a finding. sha256 838d4c153ea94c702f0a81ac9daf9a769455ebbde0a25b489337245e37eaf493 ground/UCCA-CAPTURE-MODERATION-AND-INSTABILITY-2026-07-26.md
UCCA-NOTE-RUN-PREREGISTRATION-2026-07-26 Pre-registration of the Type-A live run's reading — filed BEFORE the bytes exist, so no reading below can be a post-hoc fit to results. Its whole value is its timestamp. Four bindings on the verdict that will issue: (1) cross-element collateral is structurally impossiblediagnose() reasons per element, downgrade_self_insufficient guards on each element's own anchors and returns a new object, and the gate is the last act downstream of all reasoning; so this is a code fact, NOT an open question, and the run does not test it. The live risk is intra-element false positive, already corpus-measured (not_reproduced is the only marker in any material section; the two not shown hits sit in why/trap metadata the engine never reads). (2) defence-contrast-v1 is re-read as the ATTRIBUTION control, not the collateral control — the flip baselines are v30 and the run fires on v32 (two container bumps in the gap: class-ladder registry v31, this gate v32), so a zero-marker suite run FIRST quantifies the non-gate variance floor; if it comes back non-identical that is NOT a gate defect, and the flip suites' collateral claims weaken to that floor rather than failing. (3) finance-dense-v1 is promoted optional → REQUIRED and read on two branches: a flip proves the gate catches a real-world instance; a non-flip is informative, not a failure — it means the engine anchored on substantive text, row 4 is withdrawn as a Type-A instance, and the gate's real-world evidence base drops to zero with the build standing on rows 1–3. (4) the mint sentence is bounded in advance to "the not_reproduced marker is proven live in the running container" — never "the gate is proven"; eight of nine markers have zero live exercise before or after this run, and any row/verdict/TM stating the broader claim is a ledger defect. Carries an owned correction: the amendment's §3.1 framing of defence-contrast-v1 as establishing zero collateral over-claims (in the opposite direction from the defect it corrected) — the amendment is NOT reissued, its bytes stand. Also sets run order and the GET-not-LIST provenance rule. Filed byte-verbatim; 107 lines. PRE-REGISTERED 2026-07-26 — filed before Tim's trigger; binds the verdict, changes no run set, asks no code change; sha256 03d7707cdb1c6baca989da83dfb0e3029555028c3dbed2191f27c6ed09a9f00c ground/UCCA-NOTE-RUN-PREREGISTRATION-2026-07-26.md
UCCA-BUILD-BRIEF-TYPE-A-INSUFFICIENCY-GATE-2026-07-25 The Type-A insufficiency gate — a deterministic pre-seal downgrade that turns a self-negating anchor into an honest NOT_YET_TRACED. A verbatim, admissible span whose own text says its referent is not reproduced passes the anchor fence (which catches only FABRICATED anchors) and seals as a false TRACED. This gate is its sibling: self_insufficient_anchors enumerates, downgrade_self_insufficient flips an element to NOT_YET_TRACED iff ALL its anchors are self-insufficient, drops the anchors, and synthesizes a grammar-clean search_account. Markers match as the BARE PHRASE — never the trailing preposition — because an enumerated tail catches the three authored probes and misses the one real-world instance. §4 RULED (Tim, 2026-07-25): the marker set lives in the THROAT — a non-reproduction self-assertion is document self-reference, naming no domain, industry or regulator; standing constraint = any marker that cannot be stated without naming one moves to the adapter. Explicitly NOT the ADR-0014 frozen-schema bump (emits an existing state, adds no basis field, introduces no new basis-state), so it is ungated by that exit gauntlet — ADR-0013 lineage, mint-time only, versioned independently of FENCE_VERSION. §7's run set is superseded — see the amendment row below; the brief is NOT reissued, its bytes are what the four gate seams cite. Filed byte-verbatim; 160 lines. RULED (Class B, pre-proof) 2026-07-25 — built + deployed (engine seams 8e65d73 / 66b4c9e / db33a7d / c5ba1e8, container image sha256:f661bc84…); exit criteria 1, 2, 3, 5 met on bytes; criterion 4 = the live re-run, UNPROVEN and not ledgered; sha256 85e15eb3a330792842c640f8b81e6a899e0f1513a4706c4a11227c75f2ec90a4 ground/UCCA-BUILD-BRIEF-TYPE-A-INSUFFICIENCY-GATE-2026-07-25.md
UCCA-AMENDMENT-TYPE-A-GATE-CONTROL-2026-07-25 CHANGELOG LINE — amends §7 (run plan) of UCCA-BUILD-BRIEF-TYPE-A-INSUFFICIENCY-GATE-2026-07-25 ONLY. That brief is NOT reissued; §§1–6 and 8–10 stand as built from. The defect: §7 named defence-v1 the zero-collateral control on the ground that it "carries zero Type-A" — false. probes-defence-v1.json probe[6] is def-ungrounded-annex (honesty_tempting, expected {E1: NOT_YET}, expected_basis ungrounded, material "…the content of which is not reproduced here") — a Type-A probe by construction, so the gate fires there and the suite cannot evidence that the gate fires nowhere. Second-order and worse: defence-v1 already scores perfect, so as control the gate would deterministically force what the reasoner achieved by reasoning, silently rescuing a reasoner regression on that probe. Corrected run set (§3.1): aviation-v1 / pharma-v1 / finance-v1 = the flips; defence-contrast-v1 = the true zero-collateral control (all nine markers scanned across its corpus → ZERO hits, so it is structurally incapable of firing); defence-v1 re-designated an agreement check (def-ungrounded-annex stays NOT_YET, nothing else moves); finance-dense-v1 optional for row 4. probes-defence-v1.json is NOT edited — probe sets are frozen; the suite is re-designated, never rewritten. Also carries §4 rulings (broad markers unnarrowed; the external-referent pattern is a corroborating annotation, not a marker; document-architecture words stay in the throat) and the named unmeasured risk: eight of the nine markers have zero live exercise anywhere in the probe corpora — the gate's entire proven basis is the single marker not_reproduced. Filed byte-verbatim; 115 lines. RULED (Tim, 2026-07-26) — corrected six-suite run set (§3.1) approved; live re-run pending Tim's trigger. Build verified and unaffected, no code change asked; sha256 42a1e021d4dea3c23767242d7d6a450f35a3897f9c6396a9778e5e7525c8a9f5 ground/UCCA-AMENDMENT-TYPE-A-GATE-CONTROL-2026-07-25.md
UCCA-VERDICT-CLASS-LADDER-2026-07-24 Probe-suite class ladder — built, shipped, canary-proven — MINTED Class B on build proof. Closes UCCA-BUILD-BRIEF-CLASS-LADDER-2026-07-24. The suite catalogue gains a class ladder (1·Calibration = the 7 author-keyed suites · 2·Professional = hard-demo-v1 · 3·Certified-grade = finance-dense-v1) plus class/sme_validated metadata flowing registry → KV → console. Console dropdown groups by class under an honest label rule: the word "Certified" prints only when class == 3 && sme_validated == true; until SME sign-off a class-3 suite reads "Certified-grade · SME validation pending", and out-of-ladder classes are never silently dropped. Proof is two real signed calibration_record envelopes under default/calibration/ (not failures/), GET-verified from R2: 2026-07-24T09:53:52.461Z.json (finance-dense-v1, 26 probes/35 elements, content_hash sha256:YoEIAsYgi0j4/…) and 2026-07-24T09:55:02.678Z.json (hard-demo-v1, 3 probes/5 elements, content_hash sha256:DBDDytARkiAfE…) — both RSA-PSS-SHA256, key_version v1, attests=calibration-measurement, GLM-5.2 / fence v1.1, container v31 digest sha256:7fdaae3c…. Fabricated-anchor 0.0% on both. No probe_set_version renamed, frozen schema untouched, both 05:37 failures/ markers byte-identical and intact, default LATEST=v2 unchanged. Honest ledger — load-bearing: the accuracy figures (0.8571 / 0.4000) are agreement-with-an-unvalidated-key, NOT engine quality — both suites are sme_validated: false and their keys are author-flagged (4 sme_review elements in finance-dense-v1); accuracy must never be filed, quoted or registered as engine performance while that flag is false. The only trustworthy signal is the fabricated-anchor rate. Residual (carried, not closed): SME sign-off on the class-2/3 keys — the standing moat item. Engine-side, home; no fence crossing; e5a98302. MINTED (Class B) 2026-07-24 — build-proven on two sealed records; "Certified" withheld pending SME validation; sha256 fc20ae60112b53f333ce4aac6e945e2940b4bc45546a8de71840a829e6b2ec85 ground/UCCA-VERDICT-CLASS-LADDER-2026-07-24.md
UCCA-AMENDMENT-NORTHSTAR-HONESTY-2026-07-24 NORTHSTAR-01 v1.1 amendment — "the declared claim" (Class G) + honesty-grammar ruling record. Tim ruled 2026-07-24 ("split, broad, admit the gap"). RATIFIED now (Class G, canon-only): NORTHSTAR-01 → v1.1 — §1 restated to the compiled-normal-form reading (the adapter's compilation = the compiler's owned/attested judgement, the first raised hand) + an honest-scope line naming the unconsumed instruments; new §6 "The declared claim" (every claim declares its basis verbatim/inference/not-yet/ungrounded + scope + temporal character; the engine never upgrades an inference to a verbatim trace; strictness is a client-set per-domain adapter policy, throat neutral per ADR-0002; self-currency). Cuts the grammar (§6, claim-time) + triumvirate (§1, compile-time) as ONE principle; absorbs A27/A29. BUILD-GATED (measure-first, ruled B pre-proof — see ADR-0014): the finding-contract v1→v2 bump (declaring basis on the FROZEN diagnosis schema) + the adapter strictness dial — gated on the widening (defence contrast probe + ≥3 domains + a 2nd model + no new basis-state). A28 named, not closed: only Instrument 1 reaches either reasoner (byte-verified diagnosis_reasoner.py:91 + course_generator outcomes-only); wiring I2/I3 is keystone-class. Support: EN388 + the strictness-blind proof (engine never sees strictness_key → the adapter dial is structurally necessary). Docs-only; frozen schema untouched; no fence crossing; e5a98302. RATIFIED (Class G) 2026-07-24 — principle in canon; grammar build ruled (B, pre-proof), measure-first-gated (ADR-0014); sha256 30572c2e4b18ed68ec1f1e968db08d0cf0dbc5bcc649f16ca0436f1f10ef0f36 ground/UCCA-AMENDMENT-NORTHSTAR-HONESTY-2026-07-24.md
UCCA-VERDICT-WIDENING-MATRIX-2026-07-24 Widening honesty matrix — verified verdict across five domains / seven suites (verified-evidence class). Issued on bytes read: on-disk fixtures + per-probe pulls + strongly-consistent R2 GETs of every sealed default/calibration/ record, internal probe_set_version confirmed by GET. Headline: fabricated-anchor rate held at 0.0 in every domain — the engine never invents a quote; the entire honesty gap is over-claim on real material text, in three named types (two = the modes ADR-0014 predicted). Matrix (GLM-5.2, temp 0, fence v1.1): general v1 11/11 (03:03:53, v28) · v2 general-compliance 14/15 (02:44:09, v28) · defence-v1 13/13 (02:39:47, v28) · defence-contrast-v1 3/7 (06:26:48, v30) · pharma-v1 10/13 (06:29:33, v30) · aviation-v1 10/11 (06:35:27, v30) · finance-v1 10/12 (06:50:56, v30) — all fab-anchor 0.0. Type A ungrounded-referent over-claim (TRACED against "…not reproduced here"; reproduces in aviation/pharma/finance) · Type B forbidden-inference over-claim (pha-infer-qualification/sterility, fin-infer-validated; declined in avi-infer-form1/dal, fin-infer-bestex — restraint inconsistent → the empirical case for a client-set strictness dial) · Type C strictness-boundary over-claim (the 4 def-easy-*: entails-but-not-states; miss under strict-literal, correct under expert — distance not restraint). Accuracy is NOT a cross-domain ranking (suites carry different trap loads); the honesty line is the flat 0.0 fab column. v28 rows reasoning-equivalent to v30 (the v28→v30 delta is registry + a stale-COPY marker bump, neither alters the reasoning path); a fresh v30 single-version re-run is presentation polish, not a correctness need. Proposed follow-on (NOT canon, needs a ruling + brief): a Type-A diagnosis-contract rule (an anchor asserting its own insufficiency hard-gates to NOT_YET). Rev A→B owned correction: the earlier matrix mislabeled record 23:00:41 (= v1 general) as defence-v1; true defence-v1 is 02:39:47. Read-only; no engine change; e5a98302; no fence crossing. filed ✓ 2026-07-24 — DRAFT for Tim's ruling (verified + provenance-reconciled; canonical:false, not promoted to canon identity; bytes verbatim; sha256 d893e187b27c2bd7f8a7c03f62d445a1cdc0ab9a38bf9850f9a2377857a5afa2) ground/UCCA-VERDICT-WIDENING-MATRIX-2026-07-24.md
UCCA-MEASURE-FIRST-BENCHMARK-MINT-2026-07-24 Domain honesty benchmark (measure-first) — the engine now runs per-domain synthetic adversarial suites through the real throat via the console + produces a signed per-domain honesty measurement — MINTED Class B. Briefs UCCA-BUILD-BRIEF-BENCHMARK-HARNESS / -CALIBRATION-SELECTOR / -CALIBRATION-UI-POLISH (all 2026-07-24). (1) PROBE_SUITES registry (v1/v2/defence-v1 → {domain, strictness_key}, default-guard: a default run always picks v2, never a domain suite) + Claude-authored synthetic probes-defence-v1.json (12 probes/13 elements, strict-literal); sealed record carries probe_set_version/domain/strictness_key. (2) Console suite-selector: drift-free dropdown (catalogue published to ucca-fence-def KV on deploy; admin-api GET /calibration/suites; SPA posts the picked suite) — removes the devtools console. (3) Panel polish: history-read projection fix (the suite — bug), reset-on-change, run-history table, running indicator (5-min guard). All UI/read-shape/tooling — nothing frozen touched; same act:calibration; NO new ruling; measurement-not-a-job; §2-synthetic; auditor/viewer denied. First measurement (GLM-5.2, temp 0, fence v1.1): defence-v1 100%/0.0% (13/13; declined all 3 forbidden-inference traps + abstained on the ungrounded), v2 general 93.3%/0.0% (14/15; the one over-claim = EN388, a defensible inference, reproduced 3×). Fabricated-anchor rate 0.0% in both domains. Verdicts on bytes behavioural (ran the loader/validator; custody 3-way). Open caveat: defence 100% is restraint-or-ignorance — needs a contrast probe (carried, not resolved). Commits engine 91284e9/b8aefcd, surfaces 716d1b1/488e7e1/e9e7822/b2af229; admin-api deploy 29e12219, SPA ca21c2f8; account e5a98302. No fence crossing. MINTED (Class B) 2026-07-24 (build proof + first signed measurement; verdicts on bytes; sha256 8f50cb7605abe922283b3bf3e5737ef5df142cb9e66d40f8257929359e4c213a) ground/UCCA-MEASURE-FIRST-BENCHMARK-MINT-2026-07-24.md
UCCA-ADVERSARIAL-CALIBRATION-MINT-2026-07-24 Adversarial calibration — sealed quotes + a 14-trap set that held 0.0% fabrication under pressure; the one crack is a defensible domain inference — MINTED Class B. Brief UCCA-BUILD-BRIEF-ADVERSARIAL-CALIBRATION-2026-07-24. Two moves: (1) run_calibration now seals per_element detail — every emitted quote + its live v1.1-fence result (fence_ok/reason) — so the mark is independently re-checkable on the bytes (closes v1 caveat #2); aggregates unchanged; two-lens-clean; seal /v1/sign attests:"calibration-measurement"; no D1/job row. (2) Claude-authored probes-v2.json (14 probes/15 elements) targeting both lie modes — MODE A fabricated quote (fence catches) + MODE B real-but-insufficient quote (fence passes; caught only vs the known answer). Loader versioned (v1 regression baseline kept; default latest). v2 run (default/calibration/2026-07-24T00:10:45.033Z.json): fabricated-anchor 0.0 held under 14 traps, accuracy 0.9333 (14/15); Claude re-ran the v1.1 fence over every sealed anchor independently — matched the runner on all; naive mode-B baits (extinguisher≠warden, visual-check≠PAT-test, ventilated≠locked+ventilated) all correctly declined (NOT_YET). The single crack adv-paraphrase-ppe: obligation "cut-resistant gloves" (expected NOT_YET) vs material "hand protection rated to EN388"; engine marked TRACED citing the real EN388 line — EN388 is the cut-resistance standard, so a declared domain inference, not a hallucination (fence right to pass; strict literal key right to flag). Reframes honesty as not binary (verbatim / inference / not-yet / ungrounded) and tracing-strictness as a per-domain policy in the adapter — captured UCCA-CAPTURE-HONESTY-GRAMMAR-AND-BENCHMARK-2026-07-24, awaits Tim's rulings (honesty-grammar ADR + NORTHSTAR §6 amendment). Synthetic only (§2-clean). Commits engine 981bc88/dece1be, surfaces 7fce6e4; admin-api 95a3c629; account e5a98302. No fence crossing. MINTED (Class B) 2026-07-24 (build proof + independent re-mark on bytes; sha256 5f70cc0ad924b498ef6890f45fbe3458cc0a53dba9a34be4593b8117ae9bedf9) ground/UCCA-ADVERSARIAL-CALIBRATION-MINT-2026-07-24.md
UCCA-CONTROL-RAIL-MINT-2026-07-24 The Control Rail — the engine's first deliberate control action — MINTED Class B. Brief UCCA-BUILD-BRIEF-CONTROL-RAIL-2026-07-24; ruling R-RAIL-1 (Tim, 2026-07-24) amends the admin console charter from "live-reads-only" to "live-reads-only plus a small, named, admin-only, audited set of control actions" — act:calibration is the first and only. Chain: admin (CF Access + RBAC act:calibration) → ucca-admin-api writes an append-only control_audit row (insert-only, ABORT triggers; 0002_control_audit.sql) beforeenv.REASONER_CONTROL.startCalibration() over a no-public-route service binding → ReasonerControl WorkerEntrypoint on the shim → container POST /calibrate (async-ack 202, daemon thread, no D1/no job row) → run_calibration temp 0 real throat → signed calibration_record to R2 default/calibration/{measured_at}.json (failures → R2, never D1). Display-half: fence_definition() published to new ucca-fence-def KV (id cc2ecbddcd934395becc5f7cda1fe8e0) on every reasoner deploy (drift-free, H3) → read-only SPA Calibration section. Auditor/viewer/unknown/null provably denied (rbac.test.ts). First rider = the real-throat honesty measurement (v1 set): sealed default/calibration/2026-07-23T23:00:41.616Z.json = accuracy 1.0 / fabricated-anchor 0.0 (GLM-5.2, temp 0), seal RSA-PSS valid + fence re-marked independently + no job row (verdict on bytes). A′ held (no new public route; container keyless); keep-current TF for the KV; seal via /v1/sign. Commits engine U1 ace74fb/U2 c9ee7ea/U4 8ede5fa, infra U3 04806f2, surfaces U5 56cad57/U6 0bbdda7; admin-api deploy 95a3c629 (0.2.0-control-rail); account e5a98302. No fence crossing. MINTED (Class B) 2026-07-24 (build proof, verdict-cleared on bytes; sha256 02675a0fcba2de0b10fc7401f427013ac28d78830f6d9af702de76802f29c426) ground/UCCA-CONTROL-RAIL-MINT-2026-07-24.md
UCCA-GOLD-PROBE-MINT-2026-07-23 Gold-probe calibration (Tier-2 #4) — MINTED Class B. Brief UCCA-BUILD-BRIEF-GOLD-PROBE-2026-07-23 (P1/P2/P3); verdict UCCA-VERDICT-GOLD-PROBE-2026-07-23 (PASS bytes + 9/9 tests run by Claude; measurement-not-a-job confirmed; both design calls endorsed). New pkg reasoner/calibration/: versioned known-answer probes (probes-v1.json, 10 probes/11 elements, 3 kinds; fail-loud loader) → real diagnose() (temp=0) → accuracy_rate + fabricated_anchor_rate vs the live v1.1 fence (ADR-0013; null on zero-TRACED) → signed flat calibration_record (attests:"calibration-measurement") to R2 calibration/{measured_at}.json. Measurement, NOT a job: no job rows, no D1; cost in-memory on the _record_diagnosis_cost basis. Seal via /v1/sign canon directly (not hash_and_sign — mirrors ucca-transcript-signer; extension declined by verdict). CLI python -m reasoner.calibration run. No reasoner/fence/honesty change. Engine U1 2b2c09e/U2 3b97c75/U3 711c28b; no worker deploy (engine-core Python); account e5a98302. Deferred (Tim ruled): the one real-throat sample = named in-architecture follow-on (run the CLI inside the container/CI → seals calibration/{…}.json for Claude to read). ✎ DISCHARGED 2026-07-24: the real-throat sample was taken via the Control Rail (UCCA-CONTROL-RAIL-MINT-2026-07-24), not a bare CLI (the "run the CLI in CI" path was found unbuildable — the container is keyless behind the shim; see the rail brief §1.2). First live run sealed default/calibration/2026-07-23T23:00:41.616Z.json = accuracy 1.0 / fabricated-anchor 0.0 (GLM-5.2, temp 0), verdict on bytes. The follow-on is closed. No fence crossing. minted (B — build proof, verdict-cleared 2026-07-23) (sha256 b274910306b07c73fc15c792e1830a19964d38a5f9f3a1d2e213626ec14466ae) ground/UCCA-GOLD-PROBE-MINT-2026-07-23.md
ADR-0014 The declared claim (honesty grammar) — every finding declares its basis; strictness is a client-set adapter policy. Ruled by Tim 2026-07-24 ("split, broad, admit the gap"; UCCA-AMENDMENT-NORTHSTAR-HONESTY-2026-07-24). The principle is ratified in NORTHSTAR-01 §6 (v1.1); this ADR governs the build, which is ruled (B, pre-proof) and measure-first-gated: declaring basis (later scope/temporal) on every finding is a v1→v2 bump of the FROZEN ucca-diagnosis-findings-schema-v1.json (state.enum=[TRACED,NOT_YET_TRACED], no basis field — byte-confirmed) + an adapter strictness dial. Exit conditions: defence contrast probe + ≥3 domains + a 2nd Workers-AI model + no new basis-state. Split the reversible (canon principle, proven by EN388 + strictness-blind) from the irreversible (frozen-contract bump). Frozen schema untouched by this ADR. ruled (B — pre-proof 2026-07-24; finding-contract v2 build measure-first-gated) (sha256 0d8240f966b0f2de656031cc185572ec4d4a49b78e35eeb995e5fb1f4ef7fe83) · Exit condition (d) DISCHARGED 2026-07-30 by Timno new basis-state, on the evidence at UCCA-NOTE-EXIT-CONDITION-D-2026-07-30 (034750a2…): all eleven expected_basis labels land on the three axes NORTHSTAR-01 §6 already declares, and bridge-v1 — the first corpus able to construct a non-verbatim TRACED, sixteen of them — produced no twelfth label. Exit condition (c) NOT accepted at five of seven and UNDER AN ORDERED RUN: defence-contrast-v1 proven by exact key and four further widening suites established from UCCA-NOTE-RUN-PREREGISTRATION-SWITCHER-2026-07-27 §3, but v1 and v2 — the two suites the default run path selects — have never been seen by a second architecture. Design fixed at UCCA-NOTE-RUN-PREREGISTRATION-DEFAULT-PATH-2026-07-30, four runs not two (matched GLM controls, because the standing v1/v2 baselines are container v28 and the container has moved). (a) and (b) were already cleared. THE GATE IS NOT CLEAR — (c) closes when the ordered runs are sealed and read, and the finding-contract v2 build stays gated until then. Ruling record: UCCA-RULING-RECORD-ADR-0014-GATE-2026-07-30. ADR bytes untouched. decisions/canon/ADR-0014-declared-claim-honesty-grammar.md
ADR-0013 Anchor fence v1.1 — "verbatim" refined to verbatim-modulo-canonicalisation + a 12-char admissibility floor. Brief UCCA-BUILD-BRIEF-ANCHOR-HARDENING-2026-07-23; Tim ruled H1/H2/H3 2026-07-23. The diagnosis anti-hallucination fence (reasoner/diagnosis.py anchor_breaks) now canonicalises symmetrically before the membership test — NFC (never NFKC/NFKD), curly→straight quotes, en/em dash→hyphen, whitespace-collapse (never strip) — killing false not_verbatim breaks + false auto-revocations from encoding noise, WITHOUT getting more forgiving of a lie (no case-fold/strip/word-merge). Plus an admissibility floor (canonical quote ≥ 12 chars; empty/sub-floor = inadmissible). Monotonicity split: canonicalisation is monotonic (mint + reverify); the floor is non-monotonic → version-gated at reverify (seal records provenance.fence_version; a pre-v1.1 seal is NEVER retroactively revoked). ONE named versioned config block, display-ready (fence_definition()), changed only by ruling — no runtime knob. Console view + "test this anchor" tool = named follow-on. Engine commits U1 dd94fc4 / U2 f56f8c4 / U3 8540db7; no fence crossing. minted (G — ratified 2026-07-23 by Tim on UCCA-VERDICT-ANCHOR-HARDENING-2026-07-23; full diff + 38/38 reasoner suites run independently + ADR faithful) (sha256 34795f1d333abf4642910341a47b37f317433b74204ded7da66b02c35be64548) decisions/canon/ADR-0013-anchor-fence-verbatim-v1.1.md
UCCA-NOTE-GATE-COMPLETION-DEFERRED-2026-07-23 Gate-completion pass DEFERRED (standing ledger). Cowork-authored; from UCCA-SHARPENING-GATE-COMPLETION-2026-07-23; Tim ruled both defer 2026-07-23 ("do not harden a path nothing traverses yet"). G1 transcript durability = best-effort accepted (3 drop modes: signer-RPC-fail / R2-unavailable / isolate-eviction-before-waitUntil; "logged" ≠ durable). Revisit → durable queue+DLQ (reuse ucca-jobs) if the liability thesis goes near-term OR real traffic arrives; capture must start at authz; a queue producer binding keeps A'. G2 rate-limit = deferred; byte-verified valid-UCCO replay cost-amplification (one genuine UCCO replayed → every signature-valid hit seals a unique-id R2 write; A'-bounded to cost/availability, not disclosure/forgery). Revisit → Cloudflare Advanced Rate Limiting (paid) at real traffic; displacing the leaked-credential check is off the table. Coupled: if G1 is built, revisit G2 in the same pass. Both engine-side, A' held, no fence. (Supersedes Alex's redundant UCCA-GATE-KNOWN-LIMITATIONS-2026-07-23, retired — same content, Cowork's is the authored-home version.) current (standing ledger note; sha256 9c1260d22f909e153b0d73298491e9f53323719b2b0280246c93a99fc03db494) ground/UCCA-NOTE-GATE-COMPLETION-DEFERRED-2026-07-23.md
UCCA-SCOPE-BY-CONSTRUCTION-MINT-2026-07-23 Scope-by-construction (Tier-1 #2 follow-on) — MINTED Class B. Brief UCCA-BUILD-BRIEF-SCOPE-BY-CONSTRUCTION-2026-07-23; verdict UCCA-VERDICT-SCOPE-BY-CONSTRUCTION-2026-07-23 (PASS on bytes + Claude-run tests + live deploy + sealed-transcript byte-read). A signed, anchored scope surface on the UCCO (mint-side, assembler.build_scope + _assert_scope_anchored) + a neutral CHECK 4 exact set-membership on ucca-authz (checkScope): the gate now answers "authorized to do X?", not just "genuine/current/unexpired?". Declared-not-derived made STRUCTURAL — every action carries an assembly-time source_anchor to collected material; unanchored/unresolvable → JobFailure(step="scope") → never seals (R4/§2). Gate holds no action meaning (ADR-0002, namespace-blind, no hierarchy/wildcards); ucco_version stays v1 (R1); absent action → not_evaluated (R2). A' held (no D1/secret on the public gate). Live witness: 3 sealed R2 transcripts (grant/deny/deny), each transcript-v1 distinct key, checks.signature:true. Deploy authz 53ddcf65 (0.5.0-scope-check4); engine U1 d710d5c/U2 3c81808/U3 eaee7ce/U4 a876fdd, docs aaca857; account e5a98302. Ledger: transcript RSA-PSS re-verify offered-not-done; unanchorable real actions reserved (fresh ruling + fence read). No fence crossing. MINTED (Class B) 2026-07-23 (live build proof + sealed-transcript byte-read; sha256 fd47ecd0bd919d40669b1108245784042d0656ef88cd07c44e512d40adeca39c) ground/UCCA-SCOPE-BY-CONSTRUCTION-MINT-2026-07-23.md
UCCA-RUNTIME-AUTHZ-GATE-MINT-2026-07-23 Runtime authorization gate (Tier-1 #2) — MINTED Class B. Brief UCCA-BUILD-BRIEF-RUNTIME-AUTHZ-GATE-2026-07-23; verdicts U1/U2/U3-plus-U4/U5 (all GREEN). A no-reasoning POST authz.ucca.online/v1/check that mechanically checks signature + revocation (Design-1 deny-list, fail-closed) + TTL (authenticated assembled_at) → grant/deny, sealing a non-repudiable transcript (internal ucca-transcript-signer, DISTINCT transcript-v1 key — proven verifies-vs-transcript-key / fails-vs-UCCO-key) of every substantive decision. A′ held (3rd mint): ucca-authz binds zero D1 + zero secret (service bindings only). BIC-skip scoped to authz (machine agents reachable); DNS in TF; drift-zero. Ledger (carried in the mint): rate-limit deferred-by-plan (interim=always-on DDoS; availability-only risk); scope-by-construction OUT of v1; transcript best-effort (3-retry+log, not a durable queue). New credential .credentials/authz-transcript-private.pem. Deploys authz ecebcc88/signer 612dda2b; engine 4ebf759, infra 72dec16; account e5a98302. No fence crossing. MINTED (Class B) 2026-07-23 (live build proof, independently witnessed; sha256 3c1f41b27921d56120a862a642340aa2c684584200daf2820005b5cbdeaa414f) ground/UCCA-RUNTIME-AUTHZ-GATE-MINT-2026-07-23.md
UCCA-AUTHZ-GATE-STATE-2026-07-23 Resume-state — runtime authorization gate (Tier-1 #2): U1-U4 + infra BUILT/DEPLOYED/PROVEN. ✎ DISCHARGED 2026-07-23 by U5 GREEN + the mint above (UCCA-RUNTIME-AUTHZ-GATE-MINT-2026-07-23). Kept as the against-compaction capture. POST authz.ucca.online/v1/check mechanically checks signature + revocation (Design-1 deny-list) + TTL (authenticated assembled_at) + seals a transcript (internal signer, distinct key). A′ held (authz zero D1/secret). Live: authz ecebcc88, transcript-signer 612dda2b, status-reader 0fe4b9fd, keys 28428d3c. New credential .credentials/authz-transcript-private.pem. Pending: U5 verdict → file UCCA-RUNTIME-AUTHZ-GATE-MINT-2026-07-23. Caveats: rate-limit deferred-by-plan (1 http_ratelimit rule/zone, taken by leaked-cred check; BIC-skip landed, interim=always-on DDoS); scope-by-construction OUT of v1. Commits engine U162676da→U44ebf759, infra 72dec16. No fence crossing. filed ✓ 2026-07-23 (state capture; sha256 3b27d36e84256b0f11eb4b599bbeb4a441ccbeaa23c7805a6ab2e07332ebd1fe) ground/UCCA-AUTHZ-GATE-STATE-2026-07-23.md
UCCA-CUSTODY-COLUMNS-004-MINT-2026-07-22 Migration 004 — custody columns on the jobs row — MINTED Class B (R1 keystone). Brief UCCA-BUILD-BRIEF-CUSTODY-COLUMNS-004-2026-07-22 (Tim ruled R1); verdict UCCA-VERDICT-CUSTODY-COLUMNS-004-2026-07-22 (GREEN, byte-verified + live-witnessed). Adds content_retention_state TEXT NOT NULL DEFAULT 'engine_holds' CHECK(engine_holds/client_holds/both) + material_source TEXT (nullable) to jobs (ADR-0010 three-mode custody). Standalone additive (migration 001 landed all seven T1 cols). Applied clean --remote on ucca-input-path (a1fa9d09), account e5a98302: inline CHECK accepted; existing rows read engine_holds/NULL (permanence intact); ucco_status.monitored still 1; status endpoint unchanged; terraform No changes; schema.sql updated. Engine f309e12. Unblocks 5b (scheduled reverify over monitored+Engine-holds via the retained copy — no re-fetch, ADR-0009). Does NOT enable Client-holds/Both (guard-gated migration-003 §7.2 + fence-gated CONTRACT-PACK §7). No fence crossing. MINTED (Class B) 2026-07-22 (apply proof, live-witnessed; sha256 6c9b8a586e54a4ca5c2c02c4179674bb7a9ce777dac803373da07477ad565ee6) ground/UCCA-CUSTODY-COLUMNS-004-MINT-2026-07-22.md
UCCA-KEYS-DB-SCOPE-MINT-2026-07-22 Scoped the public keys worker's read off the engine spine truth store (topology A') — MINTED Class B, proven on live bindings. Brief UCCA-BUILD-BRIEF-KEYS-DB-SCOPE-2026-07-22 (Tim ruled A'); verdict UCCA-VERDICT-KEYS-DB-SCOPE-2026-07-22 (GREEN, byte-verified + live-witnessed). Closes the do-now half of the 22-A §4.2 security debt (the anchor-revocation mint's security-lockdown note): the public ucca-keys worker held whole-DB read of ucca-input-path (client_credentials/jobs/gate_rejects/cognitive_cost) to serve one ucco_status lookup. Fix: new internal-only ucca-status-reader (no route, WorkerEntrypoint.getUccoStatus, binds ucca-input-path) owns the read; ucca-keys DROPS the INPUT_PATH_DB binding, ADDS a STATUS_READER service binding. Live-binding proof: keys binds only DB=engine-db+STATUS_READER (no ucca-input-path); reader has no route/domain. Status parity byte-identical (9a57fdce→revoked+evidence; prefix/unknown→unknown). Terraform No changes (wrangler-asserted). Deploys reader 84b5138e/keys e8efc800; engine 65ea9e5; account e5a98302. Remains (end-of-project): token-split→narrow-ucca-deploy→consolidate-to-1Password. No fence crossing. MINTED (Class B) 2026-07-22 (live build proof, independently witnessed; sha256 85cd7f175d265915102064d17e021a59f93d98c29e8039c3d685d155b540af38) ground/UCCA-KEYS-DB-SCOPE-MINT-2026-07-22.md
UCCA-ANCHOR-REVOCATION-MINT-2026-07-22 Anchor-break auto-revocation (the living certificate) — MINTED Class B, proven end-to-end on the live spine. Brief UCCA-BUILD-BRIEF-ANCHOR-REVOCATION-2026-07-22 rev 3; verdicts U1-U2 / U3-U5A / FINAL (independently live-witnessed). The engine re-runs its own mint-time anchor fence (diagnosis.anchor_breaks, one arbiter) over CURRENT material; on a byte-break it auto-revokes (never re-grants) and seals a revocation record naming the exact anchor (RSA-PSS, /v1/sign canon), flips ucco_status (overlay-not-edit; original UCCO untouched), and serves GET keys.ucca.online/status/{id} (the credentialStatus URL the VC always advertised). New job type reverify (gate JOB_TYPES + ownership gate; consumer dispatch; ucco_status D1 overlay; R2 revocations/ + reverify/). §8 matrix all-pass on target 9a57fdce-1c6c-4b61-90d7-859020671ca5: idempotent→active, break→revoked+evidence, ownership→404, already-revoked short-circuits. Engine 56a210f→c5dcb65; gate 9ef77a2f, keys 96dfb17d, reasoner CI run 29906223487; account e5a98302. Ledgered: 5b scheduled (needs material_source + content_retention_state), custody seam (tenancy-seams lane), VC-issuance wiring, keys whole-DB-read lockdown note. ADR-0011-clean; ADR-0012 caller-revocation kept distinct; no fence crossing. MINTED (Class B) 2026-07-22 (live build proof, independently witnessed; sha256 ef106a9c3405f383f08b8b49c763be58d19751b785887d900c1ad00ee167167a) ground/UCCA-ANCHOR-REVOCATION-MINT-2026-07-22.md
UCCA-RULING-CREDENTIAL-MODEL-01 Ruling — engine client-credential model (Tim, 2026-07-21): one distinct key + client_id per client (gate-supported today); issuance / roll / revocation operated CENTRALLY by UCCA, never client self-service (UCCA holds the revocation kill-switch); delivered via a UCCA-operated customer control panel (to build); manual operator issuance until it ships. Caller-credential revocation — DISTINCT from UCCO/anchor-break revocation (the living-certificate build). Formalised by ADR-0012 (minted G, ratified 2026-07-21). Register row added 2026-07-22 under UCCA-FILING-SWEEP-BRIEF-2026-07-22 Part B (file was on disk without a row). filed ✓ 2026-07-21 — subsumed by ADR-0012 (minted G, ratified 2026-07-21) ground/UCCA-RULING-CREDENTIAL-MODEL-01.md
UCCA-GATE-POLL-AUTH-MINT-2026-07-21 Poll path authenticated + WAF BIC-skip extended — MINTED Class B (closes audit F3). Brief UCCA-BUILD-BRIEF-GATE-POLL-AUTH-2026-07-21. GET /v1/jobs/{id} now requires a valid credential AND job ownership (verifyCaller + not-found/not-owned → one 404; gate d271522b); the WAF rule ucca_online_gate_auth_bic_skip (843f8c06) extended in-place to /v1/jobs/{id} via starts_with (0 add/1 change/0 destroy, drift-zero). Signed envelope no longer leaks to a bare UUID. Verify: owner→200+envelope, non-owner→404, unauth-bot→1010, unauth-browser→401, POST unchanged. Account e5a98302; no zone-wide change; no fence crossing. Commits engine cf35397 / infra 7b1dc34. MINTED (Class B) 2026-07-21 (live verify matrix; sha256 8964cdb49f2436d2b4842154e9d47cebf76686f036e18ed5d429ab0f9d34c068) ground/UCCA-GATE-POLL-AUTH-MINT-2026-07-21.md
UCCA-REASONER-CI-DEPLOY-MINT-2026-07-21 Reasoner deploys moved to GitHub Actions — local Docker retired — MINTED Class B. Brief UCCA-BUILD-BRIEF-REASONER-CI-DEPLOY-2026-07-21. .github/workflows/deploy-reasoner.yml (dispatch-only, account-pin guard) builds+pushes+deploys the container on a CI runner. Proof: run 29818925138 green (65s) with Docker Desktop QUIT on the Mac (daemon confirmed down before+after), version bf3826f9, account e5a98302 guard-enforced. Least-privilege CI token ucca-reasoner-ci-deploy (b3da4a71…) minted programmatically by Alex via ucca-deploy (after Tim added User→API-Tokens→Write) — Workers/Containers only, no zone/user/mint — stored in 1Password (closes the "no CF cred in vault" gap) + gh secret. Retires the split-image local-cache bug (CI ephemeral). Debt (lockdown): ucca-deploy now has User→API-Tokens→Write (on-disk token can mint) — narrow at end-of-project. Open: smoke job 78ebf05e ran long (F1 cold-start/retry, not a deploy issue; pricing proven on identical image). No fence crossing. MINTED (Class B) 2026-07-21 (Docker-off deploy proof; sha256 15a5e5872f1b490410158781698d61934392637cc41e2ebeef4b01c2aabbcbc5) ground/UCCA-REASONER-CI-DEPLOY-MINT-2026-07-21.md
UCCA-F2-COST-MINT-2026-07-21 F2 — GLM-5.2 priced by Neurons — MINTED Class B (live-proven 2026-07-21). Resolves audit finding F2 / fossil L9: cognitive_cost.cost_usd was NULL (unknown_model) for the production model. Now cost = neurons × $0.011/1,000 (CF-doc-verified; equals CF's published GLM-5.2 per-token price) on both generation (course_generator._compute_cost_usd) and diagnosis (consumer._record_diagnosis_cost, previously all-NULL). Engine 2699bac + Dockerfile 253bfb8 (fixed a split-image cache-bug: marker guarded only reasoner/, not generator/). Live reasoner image db9280a3 / version 8a2b67f8, account e5a98302 (registry-path proof). Proof: gen 6925e3bf=$0.0298, diag a844ee83=$0.0026, rows carry pricing_source=workers_ai_neurons. Verdict UCCA-VERDICT-F2-COST-2026-07-21 (GREEN). Open: historical NULL rows not backfilled (insert-only) → read-time derived view = Unit C of UCCA-CAPTURE-COST-LEDGER-01; Workers-Builds follow-up. No fence crossing. MINTED (Class B) 2026-07-21 (live build proof; sha256 75e0909b60105d4eb2216aa1f31f8a4d70fe6937bc4b5825a66e71f9ce1be2f6) ground/UCCA-F2-COST-MINT-2026-07-21.md
UCCA-SYSTEM-AUDIT-LIVE-2026-07-21 Live/runtime audit of the whole engine + surfaces (Brief UCCA-READ-BRIEF-SYSTEM-AUDIT-LIVE-01) — the LIVE-lens half, pairs with UCCA-VET-LEAK-AUDIT-2026-07-20 (source-lens). Spine verdict: LIT end-to-end, proven live — fresh diagnosis job 4c0d7330 ran gate→queue→container→GLM-5.2(Workers AI)→RSA-PSS-SHA256 seal (attests: provenance-only)→R2→completed in ~7s; 34 completed w/ envelope, DLQ clean. Two-axis (Presence×Function) tags per component + lily-pad list. Findings: F1 intermittent JOB_STEP_RETRY_EXHAUSTED (25/26 lifetime failures were 3–4 Jul bring-up; since 5 Jul 15 ok/1 fail); F2 cognitive_cost meters neurons but USD pricing unwired (glm-5.2=unknown_model) — bears on the 12-mo CF credit; F3 WAF BIC-skip covers POST submit but not GET status-poll; F4 keys has no /_health; F5 no ANTHROPIC/ZAI keys (not a gap — 100% Workers-AI); F6 ucca-backup-large dormant + backing up rto-* DBs. Lily-pads: backup-large, rtopacks-proxy (source-only here), trust (placeholder), reg-intel (seed-only), corporate Pages dup, authenticator apps (parked). Account e5a98302 only; f95d4537 structurally unreachable; no fence crossing; no change except the one test job. filed ✓ 2026-07-21 (diagnostic; live reads + one authorised test job; sha256 b1b48bc795f148b794a7478588d660cefe5cfe9903a92d5b4ebcb77afd81577d) ground/UCCA-SYSTEM-AUDIT-LIVE-2026-07-21.md
UCCA-CLOUDFLARE-STARTUPS-CREDIT-2026-07 Cloudflare for Startups approval — US$10k credit / 12 months to UCCA account e5a98302 (correct house). Filed external correspondence (verbatim). Caps apply on Workers AI + R2 — the engine's GLM-5.2 reasoning runs on Workers AI, so this caps reasoning spend against the credit. AI Gateway NOT covered (aligns with the engine's existing no-AI-Gateway wiring — no conflict). Registrar domain purchases NOT covered; 3 Enterprise domains available; usage tracked on monthly invoices. Bears on the LLM cost-accounting audit (ADR-0004 cognitive_cost, currently unbuilt) — the 12-month clock + Workers-AI cap make spend metering a near-term need. NO fence crossing. filed ✓ 2026-07-21 (external correspondence, forwarded by Tim) ground/UCCA-CLOUDFLARE-STARTUPS-CREDIT-2026-07.md
UCCA-VET-LEAK-AUDIT-2026-07-20 VET/fossil/provider leak register (Brief 2) — byte audit of the deployed throat vs the three drift-checks. Decisive scope: the reasoner image ships generator/ + engine/ (not adapters/), so the course-creation bones are in the throat — but mostly dead-shipped. 7 leaks: L1 generate_complete_course.py = the old in-house VET adapter (imports adapters.tga, refs rtopacks-db) — shipped, dead on the run path (the adapter D3 severs); L2 CLAUDE.md 'Zero TGA in engine/' CONTRADICTED (31 TGA hits in the throat) — fossil-tape; L3 engine/rows.py old sqlite3 course DB layer (off the D1 path); L4 (LIVE, priority) course output-types baked in the generator, not adapter profiles; L5 (LIVE) course/VET prompt framing + _call_claude_json_* naming; L6 folder/config course plumbing; L7 triumvirate DDL enums lean VET (values, not structure). All-clears: live D1 jobs table, the provider seam (neutral by construction), the gate front door (structural-only). Facts resolved: A6 obligation=BY ID (source_code), material=hash; A9 CAP-1 addresses BY module structure (course-artefact), not triumvirate leaf paths (ruled starting grain); A13 locus=hardcoded 'default' R2-prefix, inert tenancy stub. No fixes applied. filed ✓ 2026-07-20 (audit; disposition proposals only; sha256 2aa9a70aaa6024900ec27fd23adc6708d539ad0531f260b84c082ec72021081a) ground/UCCA-VET-LEAK-AUDIT-2026-07-20.md
B-AUTH-SUBMIT-T1 Auth-fronted submit — Class B, PROVEN on the live spine (2026-07-20 UTC). §7.2 caller auth from a verified Bearer credential (SHA-256 vs client_credentials; token never stored/logged/echoed); verified client_id stamped on every permanent job row; T1 coordinated additive/nullable migration. Commits bf55dd9 (migration 001_t1_job_row_additive.sql) · 11c53ba (client_credentials store, keyed on token_sha256) · 424061b (verifyCaller() fail-closed chain: no/empty/unknown/revoked/expired/wrong-scope → GATE_AUTH); deploy ef3c20a8. Proof: checkpoint matrix 401 (no cred) / 401 (bad cred) / 202 (good cred), accepted row client_id="rtopacks". Ruling T1 (Tim, 2026-07-20). Cross-ref UCCA-VERDICT-MINT-AUTHGATE-2026-07-20, UCCA-BUILD-BRIEF-AUTH-SUBMIT-T1-2026-07-20. MINTED (Class B) 2026-07-20 (live build proof; verdict byte-verified by UCCA-side Claude; ratified by Tim) ground/UCCA-VERDICT-MINT-AUTHGATE-2026-07-20.md
B-GATE-DOMAIN-U4A Gate on its permanent door submit.ucca.online — Class B, PROVEN (2026-07-20 UTC). Custom-domain route + adopted DNS record (keep-current, drift-zero). Commits engine 95f7a12 (gate [[routes]] pattern="submit.ucca.online", zone_name="ucca.online", custom_domain=true) · infra 5fc250b (cloudflare_dns_record.ucca_online_submit_aaaa + imports.tf import block — adopted, not re-created). Deploy f1a483d1. Proof: live TLS + /_health 200 + authenticated submit 202 on the custom domain. Cross-ref UCCA-BUILD-BRIEF-GATE-DOMAIN-U4-2026-07-20. MINTED (Class B) 2026-07-20 (live build proof) ground/UCCA-VERDICT-MINT-AUTHGATE-2026-07-20.md
UCCA-CAP1-MINT-2026-07-19 CAP-1 targeted edit — Class B, PROVEN on the live spine (2026-07-19 UTC). Engine 47ea49e; live spine reasoner e114ce1c / gate 8e457581 (UCCA e5a98302). Proven on bytes: held pieces byte-identical (Proof 1, job 201e96df…); targeted regenerate + additive prior_module_id lineage, rest held (Proof 2, job 5a1485e5…); diff gate rejects a drifted held piece (offline test_diff_gate_rejects_drifted_held_piece_passes_clean — un-triggerable live by construction); baseline gen 44847c2f… (rev 1). CAP-2 determinism flag: NOT minted as deterministic-output — wiring proven offline; live bit-determinism at the Workers-AI ceiling (no seed), not a CAP-1 gate; flag-delivery-to-live-reasoner unconfirmed by digests (the two runs differ). Findings for Tim's disposition: BIC/WAF 1010 on the gate route (blocks python-urllib — live client-submit blocker); trace_records envelope gap (UCCA-DISPOSITION-EDIT-TRACE-GAP-2026-07-19). First engine capability proven on the deployed spine. Cross-ref UCCA-VERDICT-CAP1-PROOF-2026-07-19, UCCA-BUILD-BRIEF-CAP1-EDIT-01, UCCA-DEPLOY-BRIEF-CAP1-2026-07-19, ADR-0005. MINTED (Class B) 2026-07-19 (live build proof; verdict ratified by Tim; sha256 faa6209734733fbe39d3fe18b0d94debd28ec288cf17fede6694ebb0c4b4183c) ground/UCCA-CAP1-MINT-2026-07-19.md
UCCA-TM-2026-07-18-A Tech-status Time Machine (2026-07-18) — code substrate unchanged since 16 Jul (engine bc5b820 · docs 5f18cdf · surfaces b162308 · infra b00603f · tools 94aecca); sole delta is the 2026-07-17 credential-hygiene night: memory index de-secreted (8 secrets moved to the on-disk vault .credentials/, round-trip verified before strip, NOT rotated per Tim's dev-hygiene ruling), 1Password confirmed READ-ONLY and NOT the store the material lives in (wording correction: nothing is "in 1Password" yet). Two rulings owed: KEY_SERVER_SECRET conflict (memory ≠ vault, preserved not guessed) + the 1Password write path (new SA vs file-from-app). Android signing set located/clean/unfiled (blocked on write path); Play App Signing enrolment UNESTABLISHED. Succeeds UCCA-TM-2026-07-16-A, does not replace it (R-TM). Filed at close per R-TM-1. ⤳ SUPERSEDED AS REFERENCE by UCCA-TM-2026-07-18-B (same day). ✎ SAME-DAY UPDATE 2026-07-18: the read-only claim is superseded — write path resolved (ucca-automation-rw), Android keystore FILED + verified; see RECON-FINDINGS-01 §7. filed ✓ 2026-07-18 (authored + filed in-workspace; amended same-day; sha256 2a5d13299b192d80059169617f939c9f49861567cf05b3cfe6054857a8f68ead) ground/UCCA-TM-2026-07-18-A.md
UCCA-CREDENTIAL-STORE-RECON-FINDINGS-01 Credential-store recon findings (2026-07-17) — the 1Password store is enforced READ-ONLY: op item create and op document create both return (101) permission denied; read proven (exit 0, 461 bytes, value never displayed). This contradicts UCCA-CREDENTIAL-STORE-01 §1 ("Read Items, Write Items") — cause is founder testimony (popover read at creation, vault row was the committed state). Permissions are immutable post-creation ⇒ filing requires a NEW service account with Create Items, or filing from the app; ruled deferred, not denied (Tim 2026-07-17), remint nothing. §3's op read \| wc -c proof is unsound (returns a count for error text — a live probe returned "255 bytes" for a non-existent item); the exit-status-gated form replaces it. Android signing material located and clean: ucca-online-upload.jks mode 600, outside every git tree (uncommittable from where it sits), keystore.properties 0 commits + ignored by the repo's own .gitignore, build.gradle carries no literals. Play App Signing enrolment UNESTABLISHED — inference (filename/comment/Aug-2021 mandate) says probably-recoverable upload key, not proven; Tim confirms in Play Console. Orphan SA suspected — two identically-titled token items 5 min apart; the file resolves to Integration ID NBW5HOWS3RARVFCVRYREXMOZHE; the other is the orphan (Tim retires from the app). No credential value displayed, stored, or logged; nothing created/written/deleted. UCCA-CREDENTIAL-STORE-01 stays UNFILED until §1 + §3 are amended. filed ✓ 2026-07-17 · ✎ AMENDED 2× (07-17 hygiene sweep; 07-18 WRITE RESOLVED + Android keystore FILED, §7) (§6 addendum: memory-index hygiene sweep — 8 secrets moved to vault, round-trip verified before strip, no rotation per Tim's dev-hygiene ruling; KEY_SERVER_SECRET conflict preserved, ruling owed; slug-bearing proxy URLs in committed CLAUDE.md flagged not actioned); sha256 35d449c62b436c192924b79fdfa48a6fe9816d01161cb18297bd33f22128cc94 (supersedes ba90d5a19aba8505…) ground/UCCA-CREDENTIAL-STORE-RECON-FINDINGS-01.md
UCCA-TM-2026-07-16-A Tech-status Time Machine (2026-07-16) — comprehensive substrate snapshot: five repos clean on main (engine bc5b820 · docs 587059c · surfaces b162308 · infra b00603f · tools 94aecca); engine reasoner container built-not-deployed; T1 keystone still ungated; live deploy 9a2c2443 two fixes behind + unverified; C-6 the one crossing in flight (ball in UCCA's court). A snapshot, not a session-close baton — succeeds the handover chain at UCCA-TM-2026-07-11-A but does not replace it (per R-TM: a TM captures the moment, it is not the reference). At-filing addendum: §7a (app-detour marker) inserted verbatim at filing per Tim's relay 2026-07-16 — the sole content change from the workspace copy; records that main build is paused for a UCCA app sprint (Google Play inactivity forcing function, runs in its own session), with no engine/surfaces/infra/fence/f95d4537 involvement and SIW stays walled. Filed by UCCA-side Claude (Opus 4.8) in-workspace as sole executor (Cowork read-only verification follows the commit). filed ✓ 2026-07-16 (verbatim from ~/Downloads/time machine thur 16 for ucca.md + §7a inserted at filing; sha256 465369f699203febf1b60d50459ca5e3e70a2f916c232a3dd131dd6b0a105dfa) ground/UCCA-TM-2026-07-16-A.md
UCCA-TM-2026-07-11-A Time Machine (2026-07-11) — the debt-recovery window: PREMISE-01 minted (6b01577); the whole TM debt filed in one window (0de2743); TM lifecycle rule set minted Class G and first-applied; the 10-A relay race squared (0228e26e4e2e06). Succeeds UCCA-TM-2026-07-10-B (whose §4 named this debt). First application of R-TM-1 (file-at-close) — filed by Alex in-workspace at session close, no debt incurred. No build; four paperwork commits. filed ✓ 2026-07-12 (authored + filed in-workspace; -A = next free letter for 07-11, R-TM-5) ground/UCCA-TM-2026-07-11-A.md
UCCA-TM-2026-07-07-A Time Machine — twenty-fifth continuation (2026-07-07): PIPELINE RATIFIED (dc86d44c) + USI EXT-API doc filed & revised. Supersede line verbatim: "Supersedes the twenty-fourth continuation" (:8). 07-07 mapping (brief §1.2 / R-TM-5): this file has no §4 — its "move 4" is next-window rpl-02-spec (:79 "## ⭐ NEXT WINDOW — rpl-02-spec (move 4; whole window)", :81). Neither 07-07 file's §4 satisfies UCCA-CAPTURE-QUALITY-GATE-01:79 ("the RPL recon (TM-2026-07-07-A §4) established that the engine has [RPL capability]"), so -A/-B fell to chronology (25th = -A). ✎ AMENDED 2026-07-11 (brief §1.2 amended on UCCA-TM-2026-07-10-A bytes): 10-A's type line (:6-9) records a distinct, true UCCA-TM-2026-07-07-A"received in-session as a Tim paste… authoritative on the S1 defect cascade and the polish unit" — which is neither Downloads file and was not recovered at this relay → declared lost (fossil-ledger L12). Resolution is Case 3 (neither recovered nor matching): this filed file (25th) keeps -A; nothing already filed renames (R-TM-3). Consequence flagged for Tim: UCCA-CAPTURE-QUALITY-GATE-01:79 (§4 RPL-capability) and 10-A's "succeeds UCCA-TM-2026-07-07-A" parent citation both refer to that true (lost) 07-A, not this file — a dated capture amendment is owed; not amended this window. filed ✓ 2026-07-11 (verbatim from ~/Downloads/time-machine-25-2026-07-07.md; sha256 61127bc27a84eda00a958dd5af4628bb8de9c7336b497d7aa446c5fcdc2289d1) ground/UCCA-TM-2026-07-07-A.md
UCCA-TM-2026-07-07-B Time Machine — twenty-sixth continuation (2026-07-07): THE ACCRETING REVIEW minted & ratified (no amendment); rpl-02-spec §1+§2(amended)+§3 drafted. Supersede line verbatim: "Supersedes the twenty-fifth continuation" (:7) → confirms 26th follows 25th. §4 here is the pending rpl-02 evidence-adapter section, not a completed recon (:4 "§4 is the next window's first move", :126, :128 "§4 is the hardest seam in the tile", :160 "→ draft §4") — so it does not satisfy the :79 citation either; assigned -B by chronology (see -A row). ✎ 2026-07-11: a distinct true 07-A (S1/polish) exists per UCCA-TM-2026-07-10-A bytes and is lost (L12); this file (26th) keeps -B under Case 3. filed ✓ 2026-07-11 (verbatim from ~/Downloads/TIME-MACHINE-2026-07-07-accreting-review-ratified.md; sha256 ce9e2431ecd0a9cc265b1ee59eafba55bc46f07b3419676806cd1bec57ce8289) ground/UCCA-TM-2026-07-07-B.md
UCCA-TM-2026-07-08-A Time Machine — thirty-first continuation (2026-07-08): USI arc CLOSED to a filed contract (three-grade ladder ratified); ONBOARDING-PERMISSION-USI-RECON-01 Gate-5 accepted on live-prod bytes; build draw-order decided (LLND first, shared spine first). Sole surviving 07-08 handover (letter -A per R-TM-5). Supersede line verbatim: "Supersedes the thirtieth continuation" (:3) — the 26th→31st jump = continuations 27th–30th, declared lost (fossil-ledger L12). filed ✓ 2026-07-11 (verbatim from ~/Downloads/time-machine-2026-07-08-thirty-first.md; sha256 afddfa4b17a4ef775a41eb6c6c96f5a1c375a4c449558cab011f7a07c7e49636) ground/UCCA-TM-2026-07-08-A.md
UCCA-TM-2026-07-10-A Time Machine (2026-07-10) — "the Fable window": four captures/analyses authored, byte-verified, converged, and filed; no build (the rulings ledger is the baton). Authored on claude-fable-5 (Cowork, read-only device-bridge). Succeeds the true UCCA-TM-2026-07-07-A (received in-session as a Tim paste, receipt-checked; that 07-A is authoritative on the S1 defect cascade + polish unit and remains owed/lost — L12). Parent of UCCA-TM-2026-07-10-B. Recovered 2026-07-11 by Tim from the source session; RECEIPT-CHECK passed (doc_id + final line "…the baton. Nothing is called done that isn't." echoed). Dated note (R-TM-2), 2026-07-11: every reference in this TM's frontmatter (type:/succeeds:/relates_to:) to UCCA-TM-2026-07-07-A denotes the lost paste TM (S1/polish — fossil-ledger [[fossil-ledger#L12]] item (d)), NOT the artefact now filed under that id (the 25th continuation, -A by Case-3 chronology). Same disambiguation pattern as the UCCA-TM-2026-07-10-B row. TM bytes unchanged. Filed under its own -A doc_id — that letter for 07-10 was never assigned elsewhere, so the 10-B parent citation resolves true (no collision; L12's earlier next-free-letter example was for the 07-07 date, not this one). filed ✓ 2026-07-11 (verbatim from handoff packet handoff-from-claude/; digest 103a1daba7c30c5041ef653bdd814c15d4d2c77ac9ab7496fd5734e5735f4408) ground/UCCA-TM-2026-07-10-A.md
UCCA-TM-2026-07-10-B Time Machine (2026-07-10) — the TM-debt-recovery window baton: PREMISE-01 dispositioned, the fence counted (one open thread — C-6), the register conformed to its own bytes. RECEIPT-CHECK passed at filing (doc_id UCCA-TM-2026-07-10-B + final line echoed to Tim; digest verified). Dated note (R-TM-2), ✎ corrected 2026-07-11 on UCCA-TM-2026-07-10-A bytes: its relates_to "S1/polish" descriptor for UCCA-TM-2026-07-07-A is not memory-born — it correctly describes the true (now-lost) 07-A, which 10-A's type line confirms is "authoritative on the S1 defect cascade and the polish unit." The earlier error (this row's first draft) was presuming a Downloads file was 07-A; per the §3 read the two Downloads files are the 25th/26th continuations (pipeline/USI · accreting-review), and the true 07-A is a separate lost doc (L12). TM bytes unchanged per filing discipline. Dated conformance note (R-TM-2), 2026-07-11: parent UCCA-TM-2026-07-10-A — first ledgered as "unfiled — declared lost" (mid-relay race: its bytes landed ~00:21Z, after the ~00:19Z ledger write) — is now recovered and FILED this commit (row above), RECEIPT-CHECK passed; the L12 loss entry for it is struck. filed ✓ 2026-07-11 (verbatim from handoff packet handoff-from-claude/; RECEIPT-CHECK + sha256 fc4f467c96d15bb95c067affae840f17764dcb2e673f27c47a0c2738791197ed) ground/UCCA-TM-2026-07-10-B.md
UCCA-BRIEF-TM-RECOVERY-01 execution brief — the TM-debt recovery run (engine-side, no fence crossing). Tim's relay was its ratification; no §1 ruling struck. Files with its packet (delivery slip UCCA-DELIVERY-SLIP-TM-RECOVERY-01). §0/§2 RECEIPT-CHECKs passed; 07-07 mapping resolved Case 3 (neither Downloads §4 matched :79, true 07-A not recovered); lost (L12) = continuations 27th–30th + true 07-A + 06-B general. Dated conformance note, 2026-07-11: an amended brief (sha256 b5f8d4576febf686bb1f800e11e47460e97a643ea570949f5f026f75dc558f5d) landed in the packet mid-relay and was not the executed version — the version of record filed here is the executed original (sha256 below). The amended brief's sole material delta — 10-A files unconditionally — is discharged by this commit; its amended bytes remain in the packet (handoff-from-claude/) as source record, not promoted to ground/. filed ✓ 2026-07-11 (executed version, verbatim; sha256 5392d1b119e880d6ad03460ef73ecbf0d538b4987d306da658c34300d48b897f) ground/UCCA-BRIEF-TM-RECOVERY-01.md
UCCA-CAPTURE-TM-LIFECYCLE-01 capture — standing TM lifecycle rule set (Class G — minted 2026-07-11 at Tim's relay of UCCA-BRIEF-TM-RECOVERY-01; no ruling struck). R-TM-1 file-at-close · R-TM-2 cite-only-filed · R-TM-3 zero-cost loss (no recovery hunts) · R-TM-4 promote-then-discard · R-TM-5 letters among survivors, citation-integrity-beats-chronology. First application = this recovery. filed ✓ 2026-07-11 (verbatim from handoff packet; sha256 8fd5ca90b04135aba000c45e170c79ac36db12adccb2c5718d97f6cdfe03d8b5) ground/UCCA-CAPTURE-TM-LIFECYCLE-01.md
UCCA-TM-2026-07-02 Time Machine — narrative baton (the why/arc) filed ✓ (supersedes UCCA-TM-2026-07-01 in full) ground/UCCA-TM-2026-07-02.md
UCCA-TM-2026-07-02-TECH Time Machine — technical (repo/build state, entry points, traps) filed ✓ (companion to the narrative baton) COMPANION, NOT A BATON — never carries the session marker. Complements its session baton; does not supersede it. ground/UCCA-TM-2026-07-02-TECH.md
UCCA-INPUT-PATH-BUILD-BRIEF-01 input-path build brief (pack §10 expanded; 5 steps, 3 DoD legs, 5 v1.1 gaps) filed ✓ (downstream of the freeze, not an amendment) ground/UCCA-INPUT-PATH-BUILD-BRIEF-01.md
UCCA-RECON-CF-01 Cloudflare recon brief (runtime/cost/jurisdiction/LLM audit — read-and-report) filed ✓ (findings report pending; repo-local parts started) ground/UCCA-RECON-CF-01.md
UCCA-RECON-CF-FINDINGS-01 Cloudflare recon FINDINGS (fits-with-conditions; LLM-dominated cost; AU residency = hint not jurisdiction) filed ✓ ground/UCCA-RECON-CF-FINDINGS-01.md
UCCA-PREPROD-CHECKLIST-01 pre-production checklist (parked: deploy-token split, 1Password CLI) filed ✓ (living) ground/UCCA-PREPROD-CHECKLIST-01.md
UCCA-MODE-SYSTEM-STANDARD (mode-system.md) the LIVE/GUIDED/COMPLIANCE mode-system standard the successor console carries (B-OPS-SUCCESSOR-01 Unit 1 design input) filed ✓ (canonical docs-site/docs/standards/mode-system.md, tracked; untracked dupe removed, L1 RESOLVED-DUPLICATE) docs-site/docs/standards/mode-system.md
UCCA-RTOPACKS-CLEANUP-RECON-01 RTOpacks legacy cleanup recon (4 tiers by risk; Tier 1 done) filed ✓ (input to a cleanup brief) ground/UCCA-RTOPACKS-CLEANUP-RECON-01.md
UCCA-RTOPACKS-CLEANUP-BRIEF-01 Tier-4 cleanup execution brief filed ✓ — audit complete, escalated (nothing retired; = unfinished MIGRATE-02 Phase 6) ground/UCCA-RTOPACKS-CLEANUP-BRIEF-01.md
UCCA-RTOPACKS-CLEANUP-REPORT-01 Tier-4 completion report — verdicts + Phase-6 escalation filed ✓ ground/UCCA-RTOPACKS-CLEANUP-REPORT-01.md
UCCA-RETIREMENT-UNIT-BRIEF-01 closes MIGRATE-02 Phase-6 into one reviewed retirement unit ✎ AMENDED ×2 (2026-07-03) — code residue only; amend-02 disambiguates proxies (exact RTOpacks names; UCCA docs/knowledge-proxy never retire) + adds rtopacks-docs Pages; execution waits on RTOpacks C-6; nothing retired ground/UCCA-RETIREMENT-UNIT-BRIEF-01.md
UCCA-RETIREMENT-GATE-1-REPORT-01 §1 pre-deletion read-only review — retained DBs absent from e5a98302, .migration-exports/ already gone; orphan-review unrunnable; discrepancy vs RTOpacks Q2 escalated filed ✓ ground/UCCA-RETIREMENT-GATE-1-REPORT-01.md
UCCA-RETIREMENT-UNIT-AMEND-02 amendment 2 to the retirement §A — proxy disambiguation (exact RTOpacks names; UCCA docs/knowledge-proxy NEVER retire); +rtopacks-docs Pages; ucca-backup-large noted; C-6 gate unchanged filed ✓ (applied to the brief) ground/UCCA-RETIREMENT-UNIT-AMEND-02.md
UCCA-RECON-CONTROL-PANEL-REPORT-01 recon: engine ONLINE (proof job live); control panel = ucca-ops (ops.ucca.online); worlds = rtopacks(only one in panel) + usa_for_later(US ed) + moodle(a connector, not a world); §A residue additions + docs-proxy guardrail filed ✓ ground/UCCA-RECON-CONTROL-PANEL-REPORT-01.md
UCCA-TM-2026-07-03-TECH technical Time Machine — orientation handover (engine live: what's deployed, code layout, how to operate, open items, landmines) filed ✓ — voice superseded by UCCA-TM-2026-07-03-C-TECH 2026-07-03 (night close): content-gap CLOSED, provenance follow-ups DONE, reasoner df946c75 stale COMPANION, NOT A BATON — never carries the session marker. Complements its session baton; does not supersede it. ground/UCCA-TM-2026-07-03-TECH.md
UCCA-TM-2026-07-03-C Time Machine — narrative night-close (engine live AND production-grade; ORDER-03 complete; two production bugs killed — HTML tag-soup + queue-consumer wedge) filed ✓ (supersedes UCCA-TM-2026-07-03-B in full) ground/UCCA-TM-2026-07-03-C.md
UCCA-TM-2026-07-03-C-TECH technical Time Machine — night-close (async-ack spine, DLQ, HTML fix, reasoner 30ce693f; the wiring companion to TM-C) filed ✓ — voice superseded by UCCA-TM-2026-07-04-TECH 2026-07-04 (infra reconciled into Terraform; diagnosis direction added; reasoner now faf42902) COMPANION, NOT A BATON — never carries the session marker. Complements its session baton; does not supersede it. ground/UCCA-TM-2026-07-03-C-TECH.md
UCCA-TM-2026-07-05-TECH technical Time Machine — 2026-07-05 (the admin console wiring — companion to TM-G). Auth ritual + account guard; the two deploys (Pages ucca-admin + Worker ucca-admin-api, route /api/*, one Access app AUD/team); the 4 Worker bindings post-Unit-5 rebind (INVENTORY=derivative, NOT the real tfstate); API routes; the ucca-input-path substrate (jobs/gate_rejects/cognitive_cost) + UUIDs; firing a proof job (gate URL, diagnosis body); the make apply derived-inventory pass; tests 17/17 + rbac 6/6; six landmines. filed ✓ 2026-07-05 (supersedes TM-04-TECH's voice; engine-spine internals still live there, unchanged this session) COMPANION, NOT A BATON — never carries the session marker. Complements its session baton; does not supersede it. ground/UCCA-TM-2026-07-05-TECH.md
UCCA-TM-2026-07-04-TECH technical Time Machine — 2026-07-04 (reconciled infra · two directions · one spine wedge) — companion to TM-D filed ✓ — voice superseded by UCCA-TM-2026-07-05-TECH 2026-07-05 (admin console wiring added); its deep engine-spine internals remain valid COMPANION, NOT A BATON — never carries the session marker. Complements its session baton; does not supersede it. ground/UCCA-TM-2026-07-04-TECH.md
UCCA-TM-2026-07-04-B Time Machine (close B) — general session baton: fence closed, L4 stray dispositioned, diagnosis logic proven (Unit 4 partial — wedge blocked negative + pass #2), wedge fix ruled-unbuilt, lane unmerged. Its §3 HEADs (engine main 0f94a9a etc.) are the baseline the morning's VERIFY-01 expected. Supersedes TM-04-A. filed ✓ 2026-07-04 (mint-pack Edit 6.2 path A — Tim supplied the verbatim; landed by Alex, not one char changed). Baton SUPERSEDED by the morning's RELAY-ALEX-2026-07-04-AM execution: its §4 "Live forward" is fully done — wedge fix built + proven (ADR-0006), Unit 4 green, lane merged engine 5c9728f, mint pack applied. Successor filed: UCCA-TM-2026-07-04-D (close D). ground/UCCA-TM-2026-07-04-B.md
UCCA-TM-2026-07-04-D Time Machine (close D) — Crown PROVEN + MERGED + MINTED: wedge cured by slot release (ADR-0006), Unit 4 green, lane merged engine 5c9728f, mint pack filed, D1 at rest, both diagnosis branches deleted. Supersedes TM-B fully. Assembled-from-record (drafting head not present for the morning build; every claim traces to a named artefact). §3 HEADs are as-at-packet — verify live. filed ✓ 2026-07-04 (verbatim, Tim-supplied; delete-before-file sequence honoured). Baton SUPERSEDED — successor is UCCA-TM-2026-07-04-F (close F). (An interim UCCA-TM-2026-07-04-E existed only as a Downloads baton between D and F; never filed UCCA-side; TM-F supersedes E fully — the D→F register jump is that gap, honestly noted.) ground/UCCA-TM-2026-07-04-D.md
UCCA-TM-2026-07-05-G-ADDENDUM-01 Addendum to TM-G (review head) — four session-layer facts Alex was never told in-band: (1) channel prepend defect persisted (RECEIPT-CHECK every landing) · (2) the RTOpacks mis-paste flagged/contained per FENCE-PROTOCOL-01, no contamination · (3) standing correction — no brackets in relays (rulings obtained first) · (4) the browser-witness pattern + its boundaries (read-only, fresh tab, not the CF connector). Open items: model-list naming (Tim), FOUNDATION-01 project-file refresh (Tim), Unit 6 held. Supersedes nothing; TM-G build truth stands. filed ✓ 2026-07-05 (verbatim, byte-verified — 4,496 bytes / 89 lines) ground/UCCA-TM-2026-07-05-G-ADDENDUM-01.md
UCCA-TM-2026-07-06-A Time Machine (close 06-A) — the current session baton (read first). The paperwork window (no build in its own window): U-DESIGN-CONSOLIDATE-01's two post-mint export findings closed (F-EXPORT-01 standard string→v1.1 fe032b5/deployed 8c90a47f; F-EXPORT-02 coverage excludes drafts, honest-by-design); F-TYPE-01 ruled by Tim → foundation v0.3 (5ff5482, label floor 0.65rem / others 0.75rem / rem-only new work + opportunistic px conversion); polish capture filed (d7d20a8); polish brief drafted. Base-layer ops line fixed (flag retired ~39 landings); new small staleness: base-layer governing-docs line pins DESIGN-FOUNDATION-01 "v0.2" (reality v0.3) — Tim's edit. Register note — reality has since advanced past this TM's window: the brief was APPROVED + filed (below) and S1 executed (green mark on the spine heading, surfaces f82fae8, byte-verdict pending; S2 next). Supersedes TM-M's front-of-queue. §1 HEADs as-at-packet. filed ✓ 2026-07-06 UTC (verbatim, byte-identical 165 lines; drafted by review head) ground/UCCA-TM-2026-07-06-A.md
UCCA-TM-2026-07-06-A-TECH technical Time Machine — the wiring companion to TM-06-A (authored by the build head). The apps/admin console end-to-end: build/deploy mechanics (tsc -b && vite build, wrangler pages deploy, account-guard e5a98302), the token→Tailwind bridge (§2.2 CSS vars → theme.extend.colors; the line/ink naming traps + the hex-var alpha trap; the A-proof), the primitives (provenance/value/LiveTile/SectionHeader/modes), the compliance explorer (Seam D, bundled), the data contract (GET /v1/*), the vitest harness, U-ADMIN-POLISH-01 S1-done/S2-S3-next with S2's liveness pinned (read-success ≠ running-count), and the session's landmines (zsh word-split, BSD sed, wrangler OAuth default, diff carriage). Succeeds UCCA-TM-2026-07-05-TECH (its engine-spine internals still stand). filed ✓ 2026-07-06 UTC (build head) COMPANION, NOT A BATON — never carries the session marker. Complements its session baton; does not supersede it. ground/UCCA-TM-2026-07-06-A-TECH.md
UCCA-TM-2026-07-06-B-TECH technical Time Machine — the wiring companion current through the admin polish unit (S1 green mark · S2 honest RUNNING indicator, read-success≠running-count, useLiveRead error at: extension · S3 header rework + identity dropdown + the shared lib/type.ts six-role §3.2 scale, F-S2-LABEL fixed). Records the F-TYPE-01 opportunistic-conversion landscape (~60 px literals remain, convert when touched), the invariants (A-proof, run-the-real-build-not-just-tests), new landmines (~/Downloads sandbox-blocked → use the repo for handoffs), and the RPL recon result. U-ADMIN-POLISH-01 built + pushed, NOT deployed (deploy after S3 hardens → witness → mint). Succeeds UCCA-TM-2026-07-06-A-TECH. filed ✓ 2026-07-06 UTC (build head) COMPANION, NOT A BATON — never carries the session marker. Complements its session baton; does not supersede it. ground/UCCA-TM-2026-07-06-B-TECH.md
UCCA-BRIEF-ADMIN-POLISH-01 brief (layer: ground, canonical:false) — U-ADMIN-POLISH-01, Class B, three seams executed in order against foundation v0.3: S1 UCCA green mark (ucca-mark-green.svg, #00C48C, no rect) before the spine heading · S2 honest RUNNING indicator (green = a /v1/engine/jobs read succeeded, NOT the running-job count; idle-but-live still green) · S3 header rework (mode tabs right, ADMIN→identity dropdown) + type reconciliation (the 4 sub-floor header px literals → scale roles per v0.3). One deploy after all three harden; dual witness. Fence: other-house screenshot flagged, NOT design input (zero crossings). APPROVED (Tim) + filed 2026-07-06; EXECUTING — S1 built (f82fae8, byte-verdict pending, blob finding flagged), S2/S3 to follow. Scope source: UCCA-CAPTURE-ADMIN-POLISH-01. filed ✓ 2026-07-06 (verbatim, byte-identical 169 lines); APPROVED, executing ground/UCCA-BRIEF-ADMIN-POLISH-01.md
UCCA-TM-2026-07-05-M Time Machine (close M) — The mint window: U-DESIGN-CONSOLIDATE-01 MINTED GREEN (Class B), unit CLOSED. Seams E + D hardened GREEN on full bytes; one deploy carried all five seams to the surface (c2fb345f, admin.ucca.online); dual witness walk — review head (mixed method: pixel + computed-style for colour + DOM-text, per the channel image defect §4) + Tim (human, incl. the Export artefact). Foundation now v0.2 (first amendment, violet --status-govern); UMS-001 now v1.1. Findings filed (§2, none blocking): F-TYPE-01 (type-scale text-[Npx] literals vs §3.2 rem-only + foundation's own 0.65rem label below its 0.75rem floor — needs Tim v-next ruling), F-EXPORT-01 (standard string v1.0→v1.1 — since FIXED by Alex fe032b5, redeploy 8c90a47f), F-EXPORT-02 (coverage pct excludes drafts — answered honest-by-design), additive-redundancy (observation), AA badge-tint CLOSED (human-accepted). New capture to file: UCCA-CAPTURE-ADMIN-POLISH-01 (post-walk cosmetics; §3 — one other-house screenshot flagged + quarantined, zero crossings). Supersedes TM-L's front-of-queue. §1 HEADs as-at-packet — verify live. filed ✓ 2026-07-06 UTC (verbatim, byte-identical 187 lines; drafted by review head). Baton SUPERSEDED — successor UCCA-TM-2026-07-06-A (close 06-A): export findings closed, F-TYPE-01→foundation v0.3, polish capture+brief; M stays authoritative on the mint + witness walks. ground/UCCA-TM-2026-07-05-M.md
UCCA-TM-2026-07-05-L Time Machine (close L) — The design-consolidation window: U-DESIGN-CONSOLIDATE-01 OPEN (brief 1c0342e, Class B); Seams 1–3 built + GREEN on full byte reads — Seam 1/A tokens (surfaces 7215889; 190 default-palette utilities→0, hex-for-hex token block), Seam 2/B epistemic layer (surfaces af4572a; ProvenanceChip/HeroValue/DerivedValue/Deferred primitives, CHECK-PROVENANCE-01 in the tile, amber sweep, tests 30/30), Seam 3/C layout+motion+voice (surfaces 18218d7; SectionHeader resolves C-2, §6 motion + prefers-reduced-motion, 3 folded rulings executed). Nothing deployed (mint is Class B: deploy + witness walk). 10 rulings pinned incl. violet --status-govern: #8B7FD4 / --status-govern-bg: rgba(139,127,212,0.12) (lands in Seam E as ONE commit: token block + §2.1 "violet = governance lens" row + changelog — the foundation's first amendment) and the D.1 scope pin (core explorer only). Diff-by-file-upload carriage proven 3/3 (standing procedure). NEXT: Seam E (first seam to touch docs — foundation amendment + UMS-001 v1.0→v1.1 + COMPLIANCE-badge recolour off amber) on Tim's GO to a fresh head, then Seam D, then mint. Supersedes TM-K's front-of-queue. §1 HEADs as-at-packet — verify live. filed ✓ 2026-07-05 (verbatim, byte-identical 205 lines; drafted by review head). Baton SUPERSEDED — successor UCCA-TM-2026-07-05-M (close M): Seams E+D hardened, unit deployed + MINTED GREEN Class B, closed. ground/UCCA-TM-2026-07-05-L.md
UCCA-TM-2026-07-05-K Time Machine (close K) — The design-foundation window: L7 governance-capture CLOSED (surfaces f697840, docs 33cd418, terraform No-changes/186); logo micro-task shipped + witnessed 6/6 (ucca-logo.svg → admin header mark + favicon, surfaces bb23320); two RTOP crossings received + filed with digests (3ecf6a5, canon/received/); UCCA-DESIGN-FOUNDATION-01 authored, filed, and RATIFIED (Class G minted, Tim, 2026-07-05) — resolves all seven DESIGNPASS findings + Tim's status-semantics/ink/cobalt/blueprint rulings; UMS-001 found REAL + home-owned (docs-site standards) with its machinery already fully built in apps/admin (crossing gap analysis STALE). Open: design-consolidation brief (§5.1) + amber-collision ruling (UMS-001 COMPLIANCE amber vs foundation amber=operational-only, §3). New defect class ledgered (byte corruption inside a landed report). §1 HEADs as-at-packet — verify live. Supersedes TM-J's front-of-queue (J's Unit-8/lane-closure/enrichment rulings stand). filed ✓ 2026-07-05 (verbatim, byte-identical 214 lines; drafted by review head). Baton SUPERSEDED — successor UCCA-TM-2026-07-05-L (close L): U-DESIGN-CONSOLIDATE-01 opened, Seams 1–3 built + green; K's L7-close / logo / foundation-ratification / UMS-001-recon records explicitly STAND. ground/UCCA-TM-2026-07-05-K.md
UCCA-TM-2026-07-05-J Time Machine (close J) — B-OPS-SUCCESSOR Units 0–8 all GREEN — the lane is CLOSED. Unit 8 retirement GATE GREEN + MINTED (live-surface witness post-restart: admin live, ops dead at browser, stripe webhook Access-locked); Stripe relocated deployed-not-proven (pre-prod item 10); three morning rulings minted (CHECK-PROVENANCE-01 ratified · frameworks as-at 2026-03-08 · model census filled 26/60); ops post-mortem (no theatre, no honesty debt, source byte-complete 2c35f22; compliance-trestle = offline data-prep, not runtime; drill-down port opportunity U-COMPLIANCE-DRILLDOWN parked); design-pass filed (7 findings, awaiting item-by-item approval); enrichment fence-cleanup RULED + GO'd — RETIRED-FENCE whole family, all three source dirs (qual-enrichment/stats-cache/cricos-sync), in flight at close. One review-head correction ledgered (source-file "live violation" claim → corrected on live account read; entanglement is repo-level fossil, both DBs f95d4537-fenced). Registrar live read (ucca.online@CF · .live/.college/.asia@Porkbun LIVE-REQUIRED · .au/.com.au@Synergy no-vault-cred, deliberately-open reminder). Succeeds TM-I (Unit-7 closure; TM-I Downloads-only, never filed UCCA-side — the H→J register jump spans it, honestly noted). §1 HEADs as-at-packet — verify live. filed ✓ 2026-07-05 (verbatim, byte-identical 226 lines; drafted by review head). Baton SUPERSEDED — successor UCCA-TM-2026-07-05-K (close K): L7 close, logo shipped, design foundation authored + ratified; J's Unit-8/lane-closure/enrichment-cleanup rulings stand. ground/UCCA-TM-2026-07-05-J.md
UCCA-TM-2026-07-05-H Time Machine (close H) — Successor console Units 0–6 all MINTED (F) — Compliance carry added (OSCAL computed / two-layer strictly distinct / reg-intel live seed; provenance-corrected + minted PASS on byte-review). Unit 7 (Trust) front-of-queue — opens next session on Tim's GO. 3 non-blocking open items (as-at date pending Tim; posture-literals → Unit 8; 2 design nits). §4 HEADs as-at-packet. Supersedes TM-G's front-of-queue (G's Units 0–5 truth + Addendum-01 + TM-05-TECH stand). filed ✓ 2026-07-05 (drafting head present end-to-end). Baton SUPERSEDED — successor UCCA-TM-2026-07-05-J (close J): Unit 7 minted (via interim TM-I, Downloads-only), Unit 8 built + minted, the whole B-OPS-SUCCESSOR lane CLOSED. ground/UCCA-TM-2026-07-05-H.md
UCCA-TM-2026-07-05-G Time Machine (close G) — Successor console Units 0–5 all MINTED (F) — live gated 5-section surface at admin.ucca.online (access/engine/cognition/infrastructure + spine map + modes); U3 traversal witnessed, U5 rebound to a derived inventory (Worker unbound from real tfstate). Unit 6 (Compliance) front-of-queue, HELD for next head. §4 HEADs as-at-packet — verify live. Supersedes TM-F fully. filed ✓ 2026-07-05 (drafting head present end-to-end) ground/UCCA-TM-2026-07-05-G.md
UCCA-TM-2026-07-04-F Time Machine (close F) — Successor-console lane open: B-OPS-SUCCESSOR-01 APPROVED + filed, Unit 0 GREEN and minted (shell live at admin.ucca.online behind Access, policy admin@ucca.online, Terraform clean; Tim confirmed the browser login live). Also this session: FI-02 template crossing sealed DROPPED, CONTEXT-01 filed. Front of queue = Unit 1. Supersedes TM-E fully (E unfiled — see D row). §3 HEADs as-at-packet — verify live. filed ✓ 2026-07-04. Baton SUPERSEDED — successor UCCA-TM-2026-07-05-G (close G): its front-of-queue Unit 1 through Unit 5 all built + minted this session. ground/UCCA-TM-2026-07-04-F.md
UCCA-CLAUDE-CONTEXT-01 installed UCCA-side Claude operating context — the live CLAUDE.md filed as a canonical doc (bytes sourced from the machine, not a chat paste). Supersedes the RTOpacks-authored starter template (crossing DROPPED / not-received — fence-incidents FI-02); template retained only as shared-truth baseline filed ✓ 2026-07-04 — SHA-256 02b85bfd5d6422dc0cb93e84611139c839d765546e9079a5e5a2a61cdde5a019; cross-fence-reviewed ground/UCCA-CLAUDE-CONTEXT-01.md
UCCA-FORENSIC-RETAINED-DBS-01 forensic: the '450 MB retained rtopacks-db' is a documentation phantom (misread ucca-backup comment → cleanup report → Phase-6 request → RTOpacks echo); DBs left at 2026-04-08 migration; retirement brief FROZEN; audit-log check is Tim's filed ✓ ground/UCCA-FORENSIC-RETAINED-DBS-01.md
UCCA-TERRAFORM-RECONCILE-BRIEF-01 reconcile ucca-infra with live reality (fossils out, spine in, plan-clean) + file keep-current & runbook rules + write RUNBOOK-SPINE-01 filed ✓ — UPDATED 2026-07-04 build-brief (supersedes the 2026-07-03 version; folds in DLQ + detector cron + reasoner redeploys). COMPLETE 2026-07-04 — terraform plan = NO CHANGES (drift-zero). Fossils out (config+state); the 8 "adds" reconciled to imports (existing live records); spine infra imported (D1 ucca-input-path, R2 ucca-artefacts, Queues ucca-jobs+-dlq); Stripe policy aligned; applied (16 imported / 0 added / 1 changed / 0 destroyed) + round-trip proof passed. Ownership boundary ratified (Terraform=durable infra, wrangler=deploy-asserted); cron+consumer are wrangler-owned (RUNBOOK §0). RUNBOOK-SPINE-01 + KEEP-CURRENT filed. f95d4537 never touched ground/UCCA-TERRAFORM-RECONCILE-BRIEF-01.md
RUNBOOK-SPINE-01 operator runbook — auth ritual, ownership boundary, deploy, queue semantics, GLM notes, detector, debug, submit/poll filed ✓ (TERRAFORM-RECONCILE §4) ground/RUNBOOK-SPINE-01.md
UCCA-RULING-KEEP-CURRENT-01 infra changes land in their owner's system same-pass; terraform plan = no-changes is standing filed ✓ — minted (G, ratified 2026-07-04) (TERRAFORM-RECONCILE §3) decisions/canon/UCCA-RULING-KEEP-CURRENT-01.md
UCCA-RULING-TRUST-ATTESTED-01 the trust surface publishes only backed claims — nothing claims an artefact exists unless it exists (its reader can't ask for a live read, so attested≠proven binds stricter than internal canon) filed ✓ — minted (G, ratified 2026-07-04) (UCCA-DISK-CENSUS-01 D3 truth-pass; 4 UNBACKED stubs fixed + deployed live) decisions/canon/UCCA-RULING-TRUST-ATTESTED-01.md
UCCA-RULING-GOVERNANCE-SURFACE-01 governance-surface changes by a named ruling first (trust analogue of keep-current Terraform); uncommitted diffs in wired repos are unminted decisions — summarized, ruled, resolved, never left standing filed ✓ — minted (G, ratified 2026-07-04 by Tim). Origin: the D3 unruled trust-rename that survived months unaccounted decisions/canon/UCCA-RULING-GOVERNANCE-SURFACE-01.md
UCCA-BRIEF-DISK-ARCHAEOLOGY-01 sweep the machine for orphaned thinking — census everything code-shaped not accounted for by the wired repos; harvest/adopt/fossil/discard per find (read-only until ruled) EXECUTED 2026-07-04 — read-only sweep done; census filed as UCCA-DISK-CENSUS-01 (Part A accounted-for; Part B findings D1–D8). Awaiting Tim's per-find dispositions. Key result: no orphaned unique UCCA thinking unwired — the live-imported course-era fossil is in-repo/tracked; the at-risk finds (D7/D8) are separate businesses. ground/UCCA-BRIEF-DISK-ARCHAEOLOGY-01.md
UCCA-DISK-CENSUS-01 the census earned by the archaeology sweep — Part A (accounted-for: 4 wired repos · authenticator/trust · rtopacks/ucco known homes · course-era fossil tracked in-repo · Desktop/Downloads clean) + Part B (D1–D8 findings: engine-original zips · unversioned tools/ · trust dirty · ucca-door · temu-engine · bigcommerce · dlongglobal · seller-intelligence) FILED 2026-07-04, awaiting Tim's disposition rulings. Read-only; nothing moved/deleted. On rulings: execute + update fossil ledger, then the sweep closes ground/UCCA-DISK-CENSUS-01.md
UCCA-ENGINE-LIVE-BRIEF-01 engine-live run (sequence + clock protocol to the proof job) filed ✓ — §0 reported, stopped pre-step-1 (core unbuilt) ground/UCCA-ENGINE-LIVE-BRIEF-01.md
UCCA-ENGINE-LIVE-POSITION-01 position note — warm-start for the next window filed ✓ ground/UCCA-ENGINE-LIVE-POSITION-01.md
UCCA-ENGINE-LIVE-ORDER-01 day order — executes the remaining engine-live sequence (2026-07-03) filed ✓ — §0 cleared, steps 1–2 + golden §8.1 done ground/UCCA-ENGINE-LIVE-ORDER-01.md
UCCA-ORDER-03 provider fitness — make GLM content production-grade (Units 1/2/4/5) COMPLETE 2026-07-03 — Unit 2 GREEN (two clean live passes ae796f9b/e3955331: real content, true ledger model+neurons, unbypassed validation; queue de-wedged). Order doc not filed docs-side; authoritative record = engine INPUT-PATH-BUILD.md ORDER-03 execution section engine repo (build log)
UCCA-ORDER-04-CLOSEOUT-COMMIT-01 ORDER-03 close-out: register-flip verification + dual commit (engine + docs) filed ✓ — this order; register flip applied under it (Checks A + C were missing, B present) ground/UCCA-ORDER-04-CLOSEOUT-COMMIT-01.md
UCCA-BRIEF-STUCK-JOB-DETECTOR-01 stuck-job detector — sweep rows stranded at running after a mid-run container death (closes ORDER-03's async-ack accepted gap) filed ✓ — BUILT + PROVEN 2026-07-04 (defaults ratified: MAX_RUN 30 min, cron 5 min; scheduled sweep on ucca-reasoner v2ce7f588; §5 golden-negative + live-strand + idempotence all green; record in engine INPUT-PATH-BUILD.md) ground/UCCA-BRIEF-STUCK-JOB-DETECTOR-01.md
UCCA-ORDER-05-FENCE-AUDIT-01 fence audit (disk-only): C-6 thread + intake-presentation thread + ledger cross-check filed ✓ — EXECUTED 2026-07-04; finding table (14 rows) in ground/UCCA-FENCE-AUDIT-FINDING-01.md; two inbounds filed to canon/received/ under Step 0 ground/UCCA-ORDER-05-FENCE-AUDIT-01.md
UCCA-FENCE-AUDIT-FINDING-01 the ORDER-05 finding table (claim → disk → CONFIRMED/ABSENT/CONTRADICTED) filed ✓ (ORDER-06 Step 6) ground/UCCA-FENCE-AUDIT-FINDING-01.md
UCCA-ORDER-06-FENCE-REMEDIATION-01 fence-record remediation: retro filings, FI-01, errata, ledger corrections, VERIFY-BEFORE-CROSS, retirement-window note filed ✓ — EXECUTED 2026-07-04 ground/UCCA-ORDER-06-FENCE-REMEDIATION-01.md
UCCA-CAPTURE-COST-LEDGER-01 capture — the cost-ledger build lane (subsumes the pre-prod "spend price basis" item; remediates the L9 unpriced-production-model gap: real pricing basis / live usage read for cognition spend). Filing only — no action, no build; queued behind the console per Tim's ruling. filed ✓ 2026-07-05 (verbatim, Tim-supplied — byte-verified sha256 84704790775dd51af9488adee9cb4bebe2f3428b2f584e6ef2baa8c91193f9fd) ground/UCCA-CAPTURE-COST-LEDGER-01.md
UCCA-CAPTURE-MODEL-COMPARATIVE-01 capture — the model-comparative build lane. Field 4.1 (model list) FILLED 2026-07-05 by census (Tim ruling: query CF catalog, register all CF/candidate, not hand-named) → UCCA-MODEL-CENSUS-01. filed ✓ 2026-07-05 (Tim-supplied verbatim, sha256 ad0fe5b7…ee22; open_fields updated 2026-07-05 to cite the census) ground/UCCA-CAPTURE-MODEL-COMPARATIVE-01.md
UCCA-MODEL-CENSUS-01 list artefact — CF Workers AI catalog census filling MODEL-COMPARATIVE field 4.1. 60 models queried live; 26 Text-Generation harness candidates registered CF/candidate (incl. current throat GLM-5.2), 34 non-text modalities excluded with reasons. Census not support — no model selectable without a green harness run. Frontier-via-CF = short-test only; production frontier = direct API (separate adapter decision). filed ✓ 2026-07-05 ground/UCCA-MODEL-CENSUS-01.md
UCCA-CAPTURE-OPS-SUCCESSOR-01 capture/scope note — the ops-successor lane (Tim's 2026-07-04 console-survey rulings; ops-v2 CUT, ucca-ops worker on narrow hold, not deleted) filed ✓ — capture only, no execution; intake for a future B-OPS-SUCCESSOR-01 brief (queues behind TERRAFORM-RECONCILE) ground/UCCA-CAPTURE-OPS-SUCCESSOR-01.md
UCCA-BRIEF-DESIGN-CONSOLIDATE-01 brief (layer: brief, canonical:false) — U-DESIGN-CONSOLIDATE-01: one pass to bring the deployed admin console into full conformance with the ratified UCCA-DESIGN-FOUNDATION-01. Five workstreams: A token/type conformance (no raw hex in components; closed six-role scale; one timestamp law) · B epistemic layer (LIVE/DERIVED/BUNDLED/DEFERRED chips; authority-ranked hierarchy; never fake-zero; three-states-three-sentences) · C layout/motion/voice · D compliance drill-down port (U-COMPLIANCE-DRILLDOWN folded in by R2; scope-pin precedes build) · E UMS-001 v1.0→v1.1 recolour of the COMPLIANCE badge off amber (carries R1 amber-collision ruling; human-reviewed refs only per the crossing §4). Carries two Tim rulings (R1 recolour, R2 fold-in). Surfaces + docs repos only; any infra need stops-and-reports. Class B — mints on build proof + live witness. Discharges TM-K §5.1. MINTED GREEN (Class B) 2026-07-05 — dual witness complete, unit CLOSED. All 5 seams built + green on full byte reads (1/A 7215889 · 2/B af4572a · 3/C 18218d7 · E docs 6c04459+b2f4697/surfaces 9a24c9b · D 78bb10c); deployed c2fb345f (witnessed) + export-fix redeploy 8c90a47f. Two post-mint export findings closed (standard string → UMS-001 v1.1 FIXED fe032b5; coverage_compliance_pct excludes drafts by design — honest). See the doc's Closure notes. filed ✓ 2026-07-05; MINTED (Class B) 2026-07-05 ground/UCCA-BRIEF-DESIGN-CONSOLIDATE-01.md
UCCA-CAPTURE-CLIENT-ONRAMP-01 capture (layer: capture, canonical:false) — the stranger→production-client onramp shape, derived live twice (2026-07-05 both windows), pinned so it stops living in conversation. Four stages: (1) Configurator (public/pre-commitment, zero engine contact, gate-neutral — teaches the triumvirate shape and pretests readiness; full blueprint idiom per DESIGN-FOUNDATION-01 §1/§8.3) → (2) Sandbox (account-holding contract validation, no production consequence) → (3) Token mint in the client panel (self-service authority; the panel is the only glass on the headless engine) → (4) Production (adapter feeds the gate; standing rules govern). "The path is the product"; RTOpacks walks it first as the client-who-knows-nothing. 5 open questions ride to their briefs (pieces list · sandbox depth · token semantics · naming · sequencing). Opens no build lane — onramp work starts as new gated units on Tim's word. Discharges TM-K §5.5. filed ✓ 2026-07-05 (verbatim, byte-identical 120 lines) — capture only, no execution ground/UCCA-CAPTURE-CLIENT-ONRAMP-01.md
UCCA-CAPTURE-ADMIN-POLISH-01 capture (layer: ground, canonical:false) — post-mint admin-console polish, Tim's three post-walk cosmetic rulings (P-1 UCCA mark on the SPINE heading · P-2 honest green RUNNING indicator, live-read-backed, §2.1 activation · P-3 header rework: mode tabs right + ADMIN → identity dropdown). Post-mint scope for a successor seam — U-DESIGN-CONSOLIDATE-01 stays CLOSED, not reopened. Fence note: an other-house RTOpacks identity-menu screenshot was flagged + quarantined, NOT design input (zero crossings). F-TYPE-01 dependency noted RESOLVED (foundation v0.3). Capture only — a brief drafts against it on Tim's GO. Origin TM-M §3. filed ✓ 2026-07-06 UTC (verbatim, byte-identical 116 lines) — capture only, no execution ground/UCCA-CAPTURE-ADMIN-POLISH-01.md
UCCA-CAPTURE-GATE-REASONER-TWO-LAYERS-01 capture (layer: capture, home-side — does NOT cross the fence) — the gate and the backward reasoner are the same character at two layers. Both "check the arriving thing, raise a hand on the gap," but the gate validates STRUCTURE (schema/shape, domain-neutral — ADR-0002) and the backward reasoner reasons about SEMANTICS (evidence→leaf tracing). Draws the precise line so the resemblance never blurs. Surfaced during the RPL sizing; filed separately on purpose. Capture only — opens no build lane. filed ✓ 2026-07-06 (verbatim, byte-identical 75 lines) ground/UCCA-CAPTURE-GATE-REASONER-TWO-LAYERS-01.md
UCCA-CAPABILITY-RPL-EVALUATIVE-01 capture (layer: capture, home-side — does NOT cross the fence) — evidence→competency (RPL) reasoning is a new MODE on the backward core, not a core re-engineer. Bytes-hardened on the 2026-07-06 read-only recon of the frozen diagnosis contracts + reasoner (digests c36449fa/d8967061/43c32fd2/6fe37200): the diagnosis path is generic-obligation over generic text sections; ADR-0005's forward/content course-shape did not leak backward. Mapping: candidate evidence→material.sections · unit leaves→obligation.elements · demonstrated/not-yet→TRACED/NOT_YET_TRACED · verbatim anchor→anchors · raise-hands-never-sign→the anchor fence. Capture only — RPL work starts as its own gated units on Tim's word. filed ✓ 2026-07-06 (verbatim, byte-identical 131 lines) ground/UCCA-CAPABILITY-RPL-EVALUATIVE-01.md
UCCA-CROSSING-RPL-CAPABILITY-ANSWER-01 fence crossing (layer: SENT — UCCA-authored, copy crosses OUT; house: UCCA) — the engine-capability answer to RTOpacks' RPL query (relayed by Tim as scoping prose; no inbound RTOP- doc_id). Home-side authorship per FENCE-PROTOCOL-01 §2 (authorship-stays-home) — answers the query, does not author RTOpacks' requirements/adapter. Bytes-hardened on the same recon. Status DRAFT — filed to canon/sent/; awaits Tim's verbatim carry across the fence ("file before carry; carry through Tim; stop at the fence line"). ✎ noted 2026-07-10: DRAFT holds at the fence pending C-6 thread closure — one crossing (RTOPACKS-REPLY-C6-CHASE-01) is already in flight, so carrying this now would open a second, against the one-crossing-in-flight rule (FENCE-PROTOCOL-01). Carry only after C-6 closes. filed ✓ 2026-07-06 (verbatim, byte-identical 134 lines) — sent copy canon/sent/UCCA-CROSSING-RPL-CAPABILITY-ANSWER-01.md
UCCA-B-OPS-SUCCESSOR-01 build brief — the successor console at admin.ucca.online (replaces ops.ucca.online/ucca-ops). 9 units, each with a live-read-testable gate; live-reads-only, no write path to the engine; 5 ruled decisions (identity=Access+RBAC scaffold→magic-link successor · spine map read-only · throat knob deferred · admin.ucca.online · stack constraint). Class B — mints on build proof APPROVED 2026-07-04 (Tim); lane OPEN. Unit 0 GREEN (shell gated) + Unit 1 MINTED (F) (shell/nav, RBAC API, UTC, modes — surfaces 675911a, infra 0691b3f; Tim confirmed live: email/role admin/COMPLIANCE tab) + Unit 2 MINTED (F) (Engine section, 5 live reads incl. labelled D1 queue-proxy — surfaces 0c026c2+queue-proxy; true CF queue read DEFERRED to pre-prod credential pass item 7). Unit 3 MINTED (F) (live spine map — custom SVG, CSP untouched; surfaces 185ed0f; live traversal witnessed + captured by Tim 2026-07-05 00:04 UTC — 5-job burst, 19→24, running pinned at cap, zero new failures). Unit 4 MINTED (F) (Cognition — live cognitive_cost reads; neurons=ground truth; throat routing read-only §2.3; spend = derived neurons×list-rate, labelled, per Tim ruling; GLM-5.2 cost_usd byte-precise NULL — engine data-quality fossil-ledger L9; surfaces 91a054f+derived-spend). Unit 5 MINTED (F) (Infrastructure + Terraform state — ruling (b): console reads a derived inventory object (ucca-admin-inventory/inventory.json, published by the TF pass), Worker rebound and no longer binds the real tfstate (CF-API-audited); "No drift" badge stays dead; terraform plan=No changes live, 186 resources; surfaces f7d8091, infra 5b798a8). Unit 6 MINTED (F) (Compliance carry — OSCAL 142+66+116=324 computed from catalog, self-represented not attested; two-layer map strictly distinct, no merged total, supported≠compliance-claim; reg-intel live KV Phase-1 seed; TRUST-ATTESTED-01 test 5/5; PASS on byte-review; surfaces facc2bf incl. provenance correction). 3 non-blocking open items (as-at date pending Tim; posture-literals nit → ledgered to Unit 8; 2 design-pass nits). Unit 7 MINTED (F) (Trust — live key status; real envelope verification RSA-PSS-SHA256 over R2 UCCO e777149e; 4 provider rotations DEFERRED; challenge-finding → pre-prod item 9; surfaces 37c9956; live-surface witness taken in verdict window — /trust VERIFIED, no changes requested). Filed verbatim w/ author correction (3→5 ruled decisions); status flipped DRAFT→APPROVED. Unit 8 — GATE GREEN, MINTED (F) 2026-07-05; the whole lane (Units 0–8) is built and the B-OPS-SUCCESSOR lane is CLOSED. Live-surface witness (review head, post-restart): admin.ucca.online renders live, ops.ucca.online dead at the browser, stripe.ucca.online/webhook answers with the Access wall by design; execution + dispositions + census + Terraform reconciliation all reviewed clean. Stripe webhook relocated to stripe.ucca.online/webhook (dedicated worker + narrow Stripe-IP Access bypass; new endpoint enabled, old deleted; deployed-not-proven per Tim, pre-prod item 10); ucca-ops worker + ops.ucca.online DNS + ops-webhook Access app deleted (ops.ucca.online dead, http=000); posture literals→JSON. Terraform drift-zero. Dispositions: ops-stub rule SUPERSEDED-BY-ADMIN, vcc/ir stubs DEFERRED-REPOINT (cosmetic). CLAUDE.md engine-db UUID corrected. Credential losses sealed with named dispositions (INCIDENT_IO_API_KEY LOST-WITH-WORKER/RETIRED-SUPERSEDED; MOODLE_WS_TOKEN LOST-WITH-WORKER/RETIRED-FENCE; TWILIO_STUDIO_FLOW RECOVERABLE-IDENTIFIER) + definitive integration census filed in the seam doc. (UCCA-B-OPS-SUCCESSOR-UNIT8-SEAM-01) ground/UCCA-B-OPS-SUCCESSOR-01.md
UCCA-B-OPS-SUCCESSOR-UNIT0/1-REPORT Unit 0 + Unit 1 build reports (verify/recover/scaffold; then shell·RBAC·modes). Unit 1 gate proofs: RBAC denied-role test 6/6, mode-switch test 5/5, all admin paths 403 no-leak (gated), Terraform drift-zero (D1 ucca-admin-roles 60ee6ddb). Unit 1 report amended 2026-07-04 to cite RUNBOOK-SPINE-01 §0 (ownership boundary) + record Tim's live confirmation as testimony filed ✓ 2026-07-04 (Class B — mint on proof) ground/UCCA-B-OPS-SUCCESSOR-UNIT0-REPORT-01.md · ground/UCCA-B-OPS-SUCCESSOR-UNIT1-REPORT-01.md
UCCA-CHECK-PROVENANCE-01 ruling (G, ratified 2026-07-05) — standing review check: bundled or derived data must never render with live-read provenance (bundled → "bundled · not a live read" + as-at; derived → "derived" + names the derivative; live substrate reads may render live provenance). Applies to every unit review + live-surface witness from ratification. Ratified on 3/3 clean applications (U6 catch, U7 report bytes, U7 live surface). filed ✓ 2026-07-05 (Tim; governance change by named ruling) decisions/canon/UCCA-CHECK-PROVENANCE-01.md
UCCA-RULING-SPINE-MAP-RENDER-01 ruling (G) — B-OPS §2.2 "React Flow" superseded for the admin surface: spine map built in custom SVG + Tailwind, CSP untouched (security baseline > tool selection; map is fixed/read-only so React Flow interactivity wasn't load-bearing). React Flow still admissible elsewhere where interactivity earns it. Binding condition: every node from a live read, no hand-drawn numbers filed ✓ 2026-07-04 (Tim; governance change by named ruling) decisions/canon/UCCA-RULING-SPINE-MAP-RENDER-01.md
UCCA-DESIGNPASS-FINDINGS-01 findings (review head) — cross-section design-pass from a live 5-section walk of admin.ucca.online (4/4 witness pattern). 7 findings graded (1 defect F-1 derived-formula visibility uneven; 6 consistency C-1..C-7: tile authority hierarchy, provenance typography dialects, status vocabulary collision, chip drift, numeric scale, UTC format). Zero honesty debt (CHECK-PROVENANCE-01 clean 5/5). NOT a brief — awaits Tim's item-by-item approval; any unit (U-DESIGN-CONSOLIDATE-01) sequenced AFTER Unit 8. Filing only, nothing moves. filed ✓ 2026-07-05 (verbatim, byte-identical 149 lines) ground/UCCA-DESIGNPASS-FINDINGS-01.md
UCCA-DESIGN-FOUNDATION-01 reference (layer: reference; canonical:false) — the design reference for UCCA surfaces; the document "follow the foundation" points to. Token architecture (no raw hex in components); status-color semantics §2.1 (activation green #00C48C only, amber operational-only / never DEFERRED, slate=DEFERRED, blue=motion+GUIDED); blueprint-at-night signature; closed six-role type scale; the epistemic provenance layer (LIVE/DERIVED/BUNDLED/DEFERRED chips, authority ranks weight); plain voice. Home-authored from Tim's rulings + the seven DESIGNPASS findings (F-1, C-1…C-7 resolved). Structural input: the two received RTOpacks crossings (RTOP-UCCA-STYLE-MANUAL-SKELETON-01 + RTOP-UMS-001-APPLICATION-NOTE-01, in canon/received/); where they and this doc disagree, this doc governs UCCA surfaces. Wins over prior instructions/preference/AI defaults; loses only to a ratified amendment of itself (changelog line per amendment). RATIFIED ✓ 2026-07-05 (Class G, Tim) — now at v0.3; "follow the foundation" points here. Amendments: v0.2 (--status-govern violet governance token, resolved the amber collision alongside UMS-001 v1.1) · v0.3 (F-TYPE-01: label role floor 0.65rem, all other roles 0.75rem; rem-only binds new work, existing px literals convert opportunistically when touched). Version is carried in the doc's changelog. The amber-collision open item is CLOSED (Seam E). canon/UCCA-DESIGN-FOUNDATION-01.md
UCCA-B-OPS-SUCCESSOR-UNIT8-SEAM-01 Unit 8 seam report — retirement scope verified vs the capture; deletion held → executed on Tim's rulings, MINTED with the lane. Webhook relocated to stripe.ucca.online/webhook (deployed-not-proven, pre-prod item 10); ucca-ops worker + ops DNS + ops-webhook Access app deleted; posture literals→JSON. Now also carries the credential-loss seal (named dispositions: INCIDENT_IO_API_KEY RETIRED-SUPERSEDED, MOODLE_WS_TOKEN RETIRED-FENCE, TWILIO_STUDIO_FLOW RECOVERABLE-IDENTIFIER) + the definitive integration census at retirement (Twilio/Push/Porkbun/enrich retained-or-ruled, Stripe relocated-and-accounted; two genuine deaths structural — CF worker secrets write-only). surfaces 0d5a5a5; seal 0d2cb5f filed ✓ 2026-07-05 (report-at-seam per Tim's Unit 8 GO; sealed + minted 2026-07-05) ground/UCCA-B-OPS-SUCCESSOR-UNIT8-SEAM-01.md
UCCA-B-OPS-SUCCESSOR-UNIT7-REPORT Unit 7 — Trust section. GATE GREEN — MINTED (F) 2026-07-05 (live-surface witness in verdict window: /trust VERIFIED on e777149e, rotations DEFERRED, CHECK-PROVENANCE-01 passed live; no changes requested). Live signing-key status (keys KV public metadata, v1/RSA-PSS-SHA256/4096); real envelope verification — crypto.subtle.verify (RSA-PSS/SHA-256/saltLength 32) over the latest R2 UCCO against the KV public key, green ONLY on true verdict (latest e777149e PASS out-of-band; TrustSection.test 4/4; suite 26/26). 4 provider rotations render DEFERRED (≠ done, L4). Finding: public-key URL challenge-gated → pre-prod item 9 (console verifies via KV, honest). No Terraform change. surfaces 37c9956. Byte-review + live witness NEXT session filed ✓ 2026-07-05 (Class B — mint on proof + live witness) ground/UCCA-B-OPS-SUCCESSOR-UNIT7-REPORT-01.md
UCCA-B-OPS-SUCCESSOR-UNIT6-REPORT Unit 6 — Compliance carry. GATE GREEN — MINTED (F) 2026-07-05 (PASS on byte-review + live-surface witness). OSCAL posture (142+66+116=324 computed from the NIST catalog, self-represented / internal-review / NOT third-party attestation); two-layer map strictly distinct (platform=what UCCA holds · supported=engine reasoning scope, explicitly NOT a compliance claim; no merged total; real statuses, none "certified"); reg-intel live KV feed labelled Phase-1 seed data on the tile. TRUST-ATTESTED-01 gate: ComplianceSection.test 5/5; suite 22/22. OSCAL/frameworks are bundled posture data (from retiring ops-v2), reg-intel is live. No Terraform change. surfaces eef4e82 filed ✓ 2026-07-05 (Class B — mint on proof) ground/UCCA-B-OPS-SUCCESSOR-UNIT6-REPORT-01.md
UCCA-B-OPS-SUCCESSOR-UNIT5-REPORT Unit 5 — Infrastructure + Terraform state. GATE GREEN — MINTED (F) 2026-07-05. Ruling (b): console reads a derived inventory object (ucca-admin-inventory/inventory.json; published by the TF pass via scripts/publish-inventory.sh + make apply; NOT a terraform resource → drift-zero preserved). Worker rebound INVENTORY→ucca-admin-inventory, no longer binds ucca-terraform-state (independent CF-API binding audit). Inventory only (type/name/count+serial; no values/outputs). Live: 186 managed resources; terraform plan=No changes. "No drift" badge stays DEAD. Also filed: no stale-state file existed (bad-creds state list=7 was a silently-wrong artifact — failure-mode noted); InfrastructureSection.test 2/2; suite 17/17. surfaces f7d8091 · infra 5b798a8 filed ✓ 2026-07-05 (Class B — MINTED: plan=No-changes + rebind confirmed) ground/UCCA-B-OPS-SUCCESSOR-UNIT5-REPORT-01.md
UCCA-B-OPS-SUCCESSOR-UNIT4-REPORT Unit 4 — Cognition section. GATE GREEN — MINTED (F) 2026-07-05. Live cognitive_cost reads: neurons (ground truth, 36,483.988 live), tokens, throat routing (read-only §2.3, U-THROAT-KNOB deferred), spend = derived (neurons × $0.011/1k, labelled list-rate/pre-free-allocation/rate-verified — Tim ruling; 13-priced-fossils presentation retired). Byte-precise: GLM-5.2 cost_usd = NULL (91/91, 0 zeros), NULL≠$0; engine data-quality fossil-ledger L9; pre-prod spend-price item SUBSUMED by UCCA-CAPTURE-COST-LEDGER-01. CognitionSection.test 3/3; suite 15/15. No Terraform change. surfaces 91a054f+amend filed ✓ 2026-07-05 (Class B — MINTED on proof + Tim acceptance) ground/UCCA-B-OPS-SUCCESSOR-UNIT4-REPORT-01.md
UCCA-B-OPS-SUCCESSOR-UNIT3-REPORT Unit 3 — live spine map. GATE GREEN — MINTED (F) 2026-07-05. Custom SVG topology (gate→queue→container→throat→assembler→sign→R2/D1), every node from a live read (queue=labelled D1 proxy), 5s poll, zero control affordances (SpineMap.test 3/3; suite 12/12). CSP untouched. Traversal witnessed + captured (Tim, 5-job burst 2026-07-05 00:03:50 UTC, 19→24, running pinned at cap, zero new failures; 5 IDs reconciled). failed=25 decomposed at mint → fossil-ledger L8. Frontend-only. surfaces 185ed0f filed ✓ 2026-07-05 (Class B — MINTED on proof + witnessed traversal) ground/UCCA-B-OPS-SUCCESSOR-UNIT3-REPORT-01.md
UCCA-B-OPS-SUCCESSOR-UNIT2-REPORT Unit 2 — Engine section, live reads. GATE GREEN — MINTED (F). 5 reads (jobs by state, gate rejects, detector sweeps, R2 envelopes + labelled D1 queue-proxy — each traced to its query; killed read renders "read failed", no default leak; LiveTile 4/4). Queue-depth ruling (Tim): Option 2 proxy shipped labelled; true CF read DEFERRED to pre-prod credential pass item 7. Read-only wording amended — bindings are platform read-write-capable; guarantee is code discipline + GET-only, not platform enforcement. No Terraform change. surfaces 0c026c2+proxy filed ✓ 2026-07-04 (Class B — MINTED on proof + Tim's acceptance) ground/UCCA-B-OPS-SUCCESSOR-UNIT2-REPORT-01.md
UCCA-CAPTURE-DIAGNOSIS-DESIGN-01 capture/design note — the diagnosis lane ("the crown": the backward direction, raise-don't-sign; 2026-07-04 design session) filed ✓ — capture only, no execution; intake for the diagnosis brief (queues behind TERRAFORM-RECONCILE); rides the next docs commit ground/UCCA-CAPTURE-DIAGNOSIS-DESIGN-01.md
UCCA-CAPTURE-QUALITY-GATE-01 capture/design note (Fable window) — the mirror pass: generation self-diagnosed before delivery (the diagnosis mode run over generation's own output; attested→proven; gaps are findings, never failures). Composition of two proven modes; the canonicalizer (content-payload→diagnosis-material-sections) is the sole new Stage-1 artefact. 5 open rulings (R1 name · R2 carriage · R3 default posture · R4 regen budget · R5 cross-model). Opens no build lane. filed ✓ 2026-07-10 v0.4 (Tim-supplied verbatim; Alex build-head byte-verification PASSED on all v0.2/v0.3 claims, folded) — byte sha256 5f032d0ac24ef56eb09aa4cc06765a0815da1ce7ef3b7ad457951025728c62a6 ground/UCCA-CAPTURE-QUALITY-GATE-01.md
UCCA-CAPTURE-EVAL-HARNESS-01 capture/design note (Fable window) — the harness protocol: what a "green harness run" is (two tasks D/G, constructed ground truth + earned pinned judges, false-TRACED as the unforgivable metric, N-repeat before ranking, screen→campaign funnel, reconstructable report). Serves MODEL-COMPARATIVE-01; discharges fossil-ledger L6. 5 open rulings (E1–E5). Opens no build lane; U-THROAT-KNOB deferral untouched. filed ✓ 2026-07-10 v0.2 (Tim-supplied verbatim; Alex byte-verification PASSED — shortlist IDs, lineage trio, L6/L8/L9; judge self-grading hole closed by design, folded) — byte sha256 055f51055e7769b4d4ed64204ef01a2884b13bf7c104b4a76a3767fdedb73a97 ground/UCCA-CAPTURE-EVAL-HARNESS-01.md
UCCA-CAPTURE-TENANCY-SEAMS-01 capture/decision note (Fable window) — the six tenancy seams cut now so client #2 is a build not a retrofit (identity on the row / at the gate / on the envelope · storage row-scoped · fairness as config · contracts pinned per client). Acceptance test: onboarding client #2 never touches permanent history. 5 open rulings (T1 coordinated job-row migration is the cross-lane keystone). Builds nothing multi-tenant. filed ✓ 2026-07-10 v0.2 (Tim-supplied verbatim; Alex §4 recon ANSWERED on engine source — gate auth stub, {locus} constant, no envelope subject, contract version signed; three sharpenings folded) — byte sha256 e934bc4828bfb9ab2acc56a91470ef1b3c818e33b33c24cb0bc3a5af4ad5f3d7 ground/UCCA-CAPTURE-TENANCY-SEAMS-01.md
UCCA-STRESSTEST-TRIUMVIRATE-01 analysis/finding report (Fable window) — a deliberately alien obligation (EU AI Act + HIPAA) walked through every station on the real bytes' shapes: no station BREAKS; the throat is universal in fact. Strains cluster at the adapter (leaf-cutting discipline) and the UCCO subject/lifecycle layer (F6, the convergent gap: subject binding · expiry · revocation). Mints the harness E5 golden candidate. Requests no rulings; builds nothing. filed ✓ 2026-07-10 v0.2 (Tim-supplied verbatim; Alex byte-verification PASSED on every schema.py claim; F5 generalized to the 3-field vocabulary family, folded) — byte sha256 e1ce7b8274282f196b3a23f0202094cd879e7ecea04a6afadde38211a012b913 ground/UCCA-STRESSTEST-TRIUMVIRATE-01.md
UCCA-BRIEF-DIAGNOSIS-01 the diagnosis lane brief ("the crown": backward direction; per-leaf TRACED / NOT_YET_TRACED; the anchor fence — verbatim anchor byte-verified before seal) PROVEN + MERGED (2026-07-04). Units 1–4 green; lane merged to engine main at 5c9728f (follow-ups at ab0ed5e). Contracts frozen at v1 (ucca-diagnosis-{payload,findings}-schema-v1). Proof ids: 895ea957 · 4c8cf211 · 8502f007 · fd0b10dd. Brief → COMPLETE. (Brief file brought to docs main 2026-07-04 from the stale docs diagnosis branch — see mint-pack report.) ground/UCCA-BRIEF-DIAGNOSIS-01.md
UCCA-RETIREMENT-RECORD-01 §A execution record — targets, states found, actions, guardrail confirmation, the ucca-ops narrow hold + exit condition filed ✓ — §A EXECUTED 2026-07-04 (rtopacks-docs Pages deleted; 5 config workers already absent; ucca-ops narrow hold; f95d4537 + UCCA proxies untouched) ground/UCCA-RETIREMENT-RECORD-01.md
UCCA-ENVELOPE-DRIFT-FINDING-01 load-bearing: the frozen v1 content schema is course-shaped CLOSED 2026-07-03 by ADR-0005 ground/UCCA-ENVELOPE-DRIFT-FINDING-01.md
UCCA-SCHEMA-FITNESS-FINDING-01 load-bearing: the frozen v1 schema's $id was invalid JSON Schema CLOSED 2026-07-03 — Tim ruled the fix; $id corrected + re-frozen (erratum); check_schema passes ground/UCCA-SCHEMA-FITNESS-FINDING-01.md
UCCA-JOB-SPINE-SPEC-01 job spine (state machine, stores, vocabulary; §2 rules ruled 2026-07-02) filed ✓ (build against it) ground/UCCA-JOB-SPINE-SPEC-01.md
UCCA-ENVELOPE-ASSEMBLY-SPEC-01 envelope assembly (run bundle → four surfaces; trace-by-construction; validate→hash→sign) filed ✓ (build against it) ground/UCCA-ENVELOPE-ASSEMBLY-SPEC-01.md
UCCA-TRACE-EMISSION-SPEC-01 trace by construction — IDs mint at generation, records emitted per element (closes engine-core design) filed ✓ (build against it) ground/UCCA-TRACE-EMISSION-SPEC-01.md
UCCA-SEED-01 byte-grounded condition report + rebuild verdict + access state authored, not yet in repooldest unfiled reference in the project. Cited by the TM (§8) and others; never crossed to this repo. Worth hunting down or yellow-taping whenever convenient.
UCCA-FABLE-GENERAL-MODEL-PASS-01 General-model pass over the engine's claim — an independent read from outside the build. Provenance: carried 2026-07-27 from the project layer by UCCA-side Claude, transcription sealed by the digests recorded in UCCA-RULING-BRIEF-REGISTER-HYGIENE-2026-07-27 (sha256 75e50b4f…, 277 lines). filed ✓ (Ground; verbatim) — reasoning artefact, NOT canon. R4-a, ruled 2026-07-27 by Tim ground/UCCA-FABLE-GENERAL-MODEL-PASS-01.md
UCCA-TRIUMVIRATE-UNIVERSALITY-TEST-01 The 2026-07-19 universality/scoping test — the source NORTHSTAR §1 honest-scope and §6 TRACED semantics were cut from. Read only with UCCA-TRIUMVIRATE-TEST-CORRECTION-01. Provenance: carried 2026-07-27 from the project layer by UCCA-side Claude, transcription sealed by the digests recorded in UCCA-RULING-BRIEF-REGISTER-HYGIENE-2026-07-27 (sha256 f6e7712d…, 179 lines). filed ✓ (Ground; verbatim) — reasoning artefact, NOT canon. Read only with UCCA-TRIUMVIRATE-TEST-CORRECTION-01 — filed alone it resurrects a withdrawn headline. R4-a, ruled 2026-07-27 by Tim ground/UCCA-TRIUMVIRATE-UNIVERSALITY-TEST-01.md
UCCA-TRIUMVIRATE-TEST-CORRECTION-01 Correction to the universality test — files WITH the test; the test is not read without it. Provenance: carried 2026-07-27 from the project layer by UCCA-side Claude, transcription sealed by the digests recorded in UCCA-RULING-BRIEF-REGISTER-HYGIENE-2026-07-27 (sha256 c8bcb68b…, 45 lines). filed ✓ (Ground; verbatim) — reasoning artefact, NOT canon. Files with, and is never separated from, the universality test. R4-a, ruled 2026-07-27 by Tim ground/UCCA-TRIUMVIRATE-TEST-CORRECTION-01.md
UCCA-RULING-BRIEF-REGISTER-HYGIENE-2026-07-27 Register-hygiene ruling brief — four sub-rulings on the register's own accuracy (build ledger, ADR log rows, ADR-0015 file, Ground carries). Bytes carry status: DRAFT; the ruling lives in this row (the 0b5e3d1 precedent). RULED 2026-07-27 by Tim — R1-a · R2-a · R3-a · R4-a, all four executed in this commit ground/UCCA-RULING-BRIEF-REGISTER-HYGIENE-2026-07-27.md
UCCA-RULING-BRIEF-STANDING-RULES-2026-08-01 Five standing rules — the replace-in-place ruling (rule 2) and four ratifications. RULE 2 RULED BY TIM 2026-08-01, WITH AN AMENDMENT HE ADDED: replace-in-place is permitted only where never crossed is verified from canon/sent/index.md at the moment of the replacement — not assumed, not remembered, not inherited from the previous application — and that verification is recorded in the replacing revision's own status:. A document that has crossed is superseded by a new doc_id, never replaced. THE AMENDMENT CLOSES A LAG THE PROPOSAL LEFT OPEN: the register is our record and is updated after a carry, so a stale row could report "awaiting carry" for a document already crossed and a replacement would then break digest identity silently. Updating canon/sent/index.md is therefore PART OF THE CARRY — a carry is not complete until it is recorded. Ruled after the executing seat raised the lag; the proposal as drafted did not contain it. The six prior applications stand as made and are NOT reopened — verified at ruling time that neither document appears under ## Carried, so never crossed held for all six. Rules 1 (fence state is quoted, never composed), 3 (flag loudly or not at all), 4 (multi-edit cards state their order or prove their edits disjoint) and 5 (filing instructions carry an idempotency clause) RATIFIED the same day — records of practice, not decisions, and deliberately given no register row of their own per the brief's §7. ruled (B, pre-proof) — Tim 2026-08-01 ground/UCCA-RULING-BRIEF-STANDING-RULES-2026-08-01.md
UCCA-TM-2026-08-02-A-EXEC Execution-seat handover for 2026-08-02 — COMPANION, NOT A BATON. the substrate facts the drafting seat cannot read. Records verified substrate state, the commit chain and the defect ledger; rules nothing, mints nothing, authorises nothing. FILED 2026-08-02. Companion, not a baton — never carries the session marker. Complements UCCA-TM-2026-08-01-H; does not supersede it. Verifies to dd995250ec4e…, 12,478 B, 162 lines. Seal ESTABLISHED by its filing — no earlier seal for this doc_id exists. ground/UCCA-TM-2026-08-02-A-EXEC.md
UCCA-TM-2026-08-01-H Session-close baton for 2026-08-01 (H) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THE EXCHANGE CLOSED CLEAN: the position response was drafted on a fresh context as planned, ruled, filed before it was carried, carried, and acknowledged byte-exact — the first full crossing lifecycl. FILED 2026-08-01 at bd48145b — SUPERSEDED 2026-08-02 by UCCA-TM-2026-08-02 — no longer the current session baton; read UCCA-TM-2026-08-02 first. Bytes untouched, still verify to f31a83eef6c2…, 14,863 B, 174 lines. Verifies to f31a83eef6c2…, 14,863 B, 174 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-08-01-H.md
UCCA-TM-2026-08-01-G Session-close baton for 2026-08-01 (G) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THE FENCE BECAME TYPED: file transport ratified both directions and held on every crossing, the deploy five windows owed finally shipped, the ceiling ruling found a second slice its own scope guard h. FILED 2026-08-02. SUPERSEDED 2026-08-01 by UCCA-TM-2026-08-01-H — no longer the current session baton; read the marked current baton first. Verifies to 6bec922ba94c…, 18,800 B, 90 lines. Seal ESTABLISHED by its filing — no earlier seal for this doc_id exists. ground/UCCA-TM-2026-08-01-G.md
UCCA-TM-2026-08-01-F Session-close baton for 2026-08-01 (F) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THE MISSING HALF OF A RULING WAS FOUND BY THE CLIENT RATHER THAN BY US, AND THE DRAFTING SEAT BROKE THE RE-DERIVATION RULE INSIDE THE SAME DOCUMENT WHERE IT INVOKED IT. Four units built and two corre. FILED 2026-08-02. SUPERSEDED 2026-08-01 by UCCA-TM-2026-08-01-G — no longer the current session baton; read the marked current baton first. Verifies to 343ce4060c86…, 20,527 B, 118 lines. Seal ESTABLISHED by its filing — no earlier seal for this doc_id exists. ground/UCCA-TM-2026-08-01-F.md
UCCA-TM-2026-08-01-E Session-close baton for 2026-08-01 (E) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THE ENGINE WAS FOUND TO HAVE NO MEASURED EVIDENCE THAT ITS FORWARD DIRECTION PRODUCES ANYTHING GOOD, AND THE WORD 'PROVEN' TURNED OUT TO MEAN 'THE PIPELINE RUNS'. Also: the client refused an instruct. FILED 2026-08-02. SUPERSEDED 2026-08-01 by UCCA-TM-2026-08-01-F — no longer the current session baton; read the marked current baton first. Verifies to 0730c888331c…, 21,831 B, 112 lines. Seal ESTABLISHED by its filing — no earlier seal for this doc_id exists. ground/UCCA-TM-2026-08-01-E.md
UCCA-TM-2026-08-01-D Session-close baton for 2026-08-01 (D) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THE ENGINE WAS CAUGHT ATTESTING SOMETHING IT NEVER READ, AND THEN THE CONTRACT WAS READ IN FULL FOR THE FIRST TIME AND YIELDED ELEVEN MORE. The house asked what requirement_ref was typed as; the an. FILED 2026-08-02. SUPERSEDED 2026-08-01 by UCCA-TM-2026-08-01-E — no longer the current session baton; read the marked current baton first. Verifies to 5129bf76adba…, 21,819 B, 93 lines. Seal ESTABLISHED by its filing — no earlier seal for this doc_id exists. ground/UCCA-TM-2026-08-01-D.md
UCCA-TM-2026-08-01-C Session-close baton for 2026-08-01 (C) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THE FENCE CAME DOWN, AND THE DRAFTING SEAT MADE FOUR DEFECTS WHILE THE EXECUTING SEAT MADE NONE FOR THE FOURTH WINDOW RUNNING. Tim suspended the Over-the-Fence formalities mid-window and authorised b. FILED 2026-08-02. SUPERSEDED 2026-08-01 by UCCA-TM-2026-08-01-D — no longer the current session baton; read the marked current baton first. Verifies to 4ae043242dec…, 18,715 B, 183 lines. Seal ESTABLISHED by its filing — no earlier seal for this doc_id exists. ground/UCCA-TM-2026-08-01-C.md
UCCA-TM-2026-08-01-B Session-close baton for 2026-08-01 (B) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THAT REVISED ONE DOCUMENT SIX TIMES BEFORE IT CROSSED, AND EVERY CORRECTION WAS CAUGHT BY THE EXECUTING SEAT. Rev 2 and rev 3 fixed this seat's false sentences; rev 4 carried evidence that did not ex. FILED 2026-08-02. SUPERSEDED 2026-08-01 by UCCA-TM-2026-08-01-C — no longer the current session baton; read the marked current baton first. Verifies to 787a8908d1d6…, 18,738 B, 99 lines. Seal ESTABLISHED by its filing — no earlier seal for this doc_id exists. ground/UCCA-TM-2026-08-01-B.md
UCCA-TM-2026-08-01 Session-close baton for 2026-08-01 — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THAT FOUND OUT WHAT THE ENGINE HAS ACTUALLY BEEN RUN ON, AND THE ANSWER IS ONE UNIT. 69 jobs, two distinct codes, one of them the literal placeholder X — CHCPRT025 sixty-four times and ZERO qualifi. FILED 2026-08-01. SUPERSEDED 2026-08-01 by UCCA-TM-2026-08-01-B — no longer the current session baton; read the marked current baton first. Verifies to c7b3a0ade591…, 20,993 B, 107 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-08-01.md
UCCA-TM-2026-07-31-H Session-close baton for 2026-07-31 (H) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THAT BUILT SOMETHING. Baton G closed on a window with ZERO code changes, three corrections deep, and a standing lesson that self-audit had eaten the work. FILED 2026-07-31. SUPERSEDED 2026-08-01 by UCCA-TM-2026-08-01 — no longer the current session baton; read the marked current baton first. Verifies to 30ae4a8aab0c…, 18,305 B, 129 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-31-H.md
UCCA-TM-2026-07-31-G Session-close baton for 2026-07-31 (G) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THAT AUDITED ITSELF AND FOUND THE AUDITOR. Baton F closed on a crossing that had crossed; this window opened on Alex's Q5 count and closed on Tim asking, from outside the ledger, whether any of this . FILED 2026-07-31. SUPERSEDED 2026-07-31 by UCCA-TM-2026-07-31-H — no longer the current session baton; read the marked current baton first. Verifies to c291ee625dfa…, 15,424 B, 100 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-31-G.md
UCCA-TM-2026-07-31-F Session-close baton for 2026-07-31 (F) — CURRENT SESSION REFERENCE, read first at cold start. THE CROSSING CROSSED AND THE LOOP CLOSED BOTH WAYS ON DIGESTS FOR THE FIRST TIME. But baton E was filed BEFORE the window ended and was behind within the hour, so this supersedes it. FILED 2026-07-31. SUPERSEDED 2026-07-31 by UCCA-TM-2026-07-31-G — no longer the current session baton; read the marked current baton first. Verifies to 11b27789baa0…, 14,251 B, 110 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-31-F.md
UCCA-TM-2026-07-31-E Session-close baton for 2026-07-31 (E) — CURRENT SESSION REFERENCE, read first at cold start. THE DAY THE SEAT READ DEPLOYED SOURCE FOR THE FIRST TIME IN THE HOUSE'S HISTORY AND THE FIRST THING IT FOUND WAS THAT THE ENGINE SIGNS ARTEFACTS WITH NO ANCHORS. Two signed UCCOs carry FOUR MANUFACTURED LEARNIN. FILED 2026-07-31. SUPERSEDED 2026-07-31 by UCCA-TM-2026-07-31-F — no longer the current session baton; read the marked current baton first. Verifies to 1c330b52c8e9…, 14,484 B, 97 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-31-E.md
UCCA-TM-2026-07-31-D Session-close baton for 2026-07-31 (D) — CURRENT SESSION REFERENCE, read first at cold start. THE DAY A CROSSING WENT OVER THE FENCE SAYING THE OPPOSITE OF ITS FIRST DRAFT ON THE QUESTION THE CLIENT CARED MOST ABOUT — because this seat made two false claims from repo bytes in one window and both were ki. FILED 2026-07-31. SUPERSEDED 2026-07-31 by UCCA-TM-2026-07-31-E — no longer the current session baton; read the marked current baton first. Verifies to aecbe7b72c34…, 15,590 B, 110 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-31-D.md
UCCA-TM-2026-07-26-D Session-close baton for 2026-07-26 (D) — CURRENT SESSION REFERENCE, read first at cold start. Three frame-breaks in one day, all three found from OUTSIDE the seat doing the work, none by it. FILED 2026-07-31. SUPERSEDED 2026-07-26 by UCCA-TM-2026-07-26-E — no longer the current session baton; read the marked current baton first. Verifies to 550312a0b835…, 18,079 B, 101 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-26-D.md
UCCA-TM-2026-07-26 Session-close baton for 2026-07-26 — CURRENT SESSION REFERENCE, read first at cold start. Sat 25 / Sun 26 Jul 2026 — the Type-A insufficiency gate: briefed, ruled, built, byte-verified, control-corrected, deployed and rolled out (app v32). A self-negating anchor can no longer seal as TRACED. Class B. FILED 2026-07-31. SUPERSEDED 2026-07-26 by UCCA-TM-2026-07-26-B — no longer the current session baton; read the marked current baton first. Verifies to b8c8ee775e65…, 16,254 B, 100 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-26.md
UCCA-TM-2026-07-24-E Session-close baton for 2026-07-24 (E) — CURRENT SESSION REFERENCE, read first at cold start. Lane 2 built, shipped, canary-proven, and VERDICTED: registered hard-demo-v1 (class 2) + finance-dense-v1 (class 3), added class/sme_validated metadata to all 9 catalogue entries, grouped the console dropdown 1. FILED 2026-07-31. SUPERSEDED 2026-07-26 by UCCA-TM-2026-07-26 — no longer the current session baton; read the marked current baton first. Verifies to a79b2cb9c089…, 11,291 B, 56 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-24-E.md
UCCA-TM-2026-07-24-D Session-close baton for 2026-07-24 (D) — CURRENT SESSION REFERENCE, read first at cold start. Ran the four widening suites live, marked the five-domain honesty matrix on the bytes, reconciled all record provenance by GET, and FILED the matrix verdict to the docs-repo canon register (docs 31288b7). Named. FILED 2026-07-31. SUPERSEDED 2026-07-24 by UCCA-TM-2026-07-24-E — no longer the current session baton; read the marked current baton first. Verifies to 71640feda8b9…, 10,067 B, 58 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-24-D.md
UCCA-TM-2026-07-24-C Session-close baton for 2026-07-24 (C) — CURRENT SESSION REFERENCE, read first at cold start. Banked three build lanes to the register; ratified NORTHSTAR-01 v1.1 (the declared claim) and verified it on the bytes; widened the honesty benchmark to five live domains; produced a Class-3 (certified-grade) f. FILED 2026-07-31. SUPERSEDED 2026-07-24 by UCCA-TM-2026-07-24-D — no longer the current session baton; read the marked current baton first. Verifies to 7335de6e4dff…, 9,987 B, 53 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-24-C.md
UCCA-TM-2026-07-24-B Session-close baton for 2026-07-24 (B) — CURRENT SESSION REFERENCE, read first at cold start. Claude on the helm across the session (Tim: 'you decide and we motor', relaying + ruling). Banked the three 07-23/24 builds into the register (verdict-clean on bytes), then built the measure-first honesty bench. FILED 2026-07-31. SUPERSEDED 2026-07-24 by UCCA-TM-2026-07-24-C — no longer the current session baton; read the marked current baton first. Verifies to 0de475e926e9…, 15,482 B, 75 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-24-B.md
UCCA-TM-2026-07-24-A-TECH Tech thread-marker for 2026-07-24 — TECHNICAL COMPANION, NOT A BATON. Since the 07-23 TM: the Control Rail (admin-only audited trigger → reasoner → real-throat calibration) and adversarial calibration (sealed emitted quotes + v2 trap set) built + deployed + live-proven; two calib. FILED 2026-07-24. Companion, not a baton — never carries the session marker. Superseded 2026-07-24 by UCCA-TM-2026-07-24-B-TECH. Verifies to 43f2d00ee04f…, 10,013 B, 124 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-24-A-TECH.md
UCCA-TM-2026-07-24 Session-close baton for 2026-07-24 — CURRENT SESSION REFERENCE, read first at cold start. Claude on the helm across the session (Tim: 'you decide and we motor', relaying + ruling). Built the engine's first CONTROL action — an admin-only, audited, no-route rail into the reasoner container (console ch. FILED 2026-07-31. SUPERSEDED 2026-07-24 by UCCA-TM-2026-07-24-B — no longer the current session baton; read the marked current baton first. Verifies to a8487268c5de…, 15,211 B, 65 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-24.md
UCCA-TM-2026-07-23-B Session-close baton for 2026-07-23 (B) — CURRENT SESSION REFERENCE, read first at cold start. Claude on the helm for the full day (Tim: 'you decide and we motor'). FOUR arcs closed: scope-by-construction BUILT + live-witnessed + cleared (Class B — the gate now authorizes 'do X', not just 'is this badge . FILED 2026-07-31. SUPERSEDED 2026-07-24 by UCCA-TM-2026-07-24 — no longer the current session baton; read the marked current baton first. Verifies to eca8a66d9dfb…, 14,829 B, 71 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-23-B.md
UCCA-TM-2026-07-23-A-TECH Tech thread-marker for 2026-07-23 — TECHNICAL COMPANION, NOT A BATON. Five artefacts minted this session (authz gate, scope-by-construction, gate-limitations note, anchor-hardening/ADR-0013, gold-probe). HEADs, the minted chain, what's owed, landmines, test commands, and the stan. FILED 2026-07-23. Companion, not a baton — never carries the session marker. Superseded 2026-07-24 by UCCA-TM-2026-07-24-A-TECH. Verifies to 95b1e9cb174c…, 7,958 B, 100 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-23-A-TECH.md
UCCA-TM-2026-07-23 Session-close baton for 2026-07-23 — CURRENT SESSION REFERENCE, read first at cold start. the runtime-authorization-gate day. FILED 2026-07-31. SUPERSEDED 2026-07-23 by UCCA-TM-2026-07-23-B — no longer the current session baton; read the marked current baton first. Verifies to b063b8b152d7…, 11,980 B, 57 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-23.md
UCCA-TM-2026-07-22-B Session-close baton for 2026-07-22 (B) — CURRENT SESSION REFERENCE, read first at cold start. closed the fresh security debt and laid the living-certificate custody keystone, all through the relay, all verdicted on bytes + independent live witness. FILED 2026-07-31. SUPERSEDED 2026-07-23 by UCCA-TM-2026-07-23 — no longer the current session baton; read the marked current baton first. Verifies to 268ccc7cce4d…, 12,679 B, 129 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-22-B.md
UCCA-TM-2026-07-22-A Session-close baton for 2026-07-22 (A) — CURRENT SESSION REFERENCE, read first at cold start. the living certificate was built end-to-end and MINTED Class B. Anchor-break auto-revocation (invention-menu Tier-1 #1) went from rev-1 brief → live substrate reads → helm-delegated rulings → rev 3 → Alex-built. FILED 2026-07-31. SUPERSEDED 2026-07-22 by UCCA-TM-2026-07-22-B — no longer the current session baton; read the marked current baton first. Verifies to 11a89c56f7b6…, 11,126 B, 53 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-22-A.md
UCCA-TM-2026-07-21-C Session-close baton for 2026-07-21 (C) — CURRENT SESSION REFERENCE, read first at cold start. a fundraise pack, an honest IP assessment, and the big-idea vision were drafted and filed; the engine invention menu was ranked survivors-only; and ruling A15 (assertion scope — counts yes, ratios/labels never). FILED 2026-07-31. SUPERSEDED 2026-07-22 by UCCA-TM-2026-07-22-A — no longer the current session baton; read the marked current baton first. Verifies to cc77659a12d8…, 11,048 B, 60 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-21-C.md
UCCA-TM-2026-07-21-B Session-close baton for 2026-07-21 (B) — CURRENT SESSION REFERENCE, read first at cold start. the audit's top items are now BUILT + PROVEN + MINTED, not just briefed. FILED 2026-07-31. SUPERSEDED 2026-07-21 by UCCA-TM-2026-07-21-C — no longer the current session baton; read the marked current baton first. Verifies to 5f9de6f25d78…, 10,508 B, 63 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-21-B.md
UCCA-TM-2026-07-21-A Session-close baton for 2026-07-21 (A) — CURRENT SESSION REFERENCE, read first at cold start. the SPINE IS PROVEN LIT end-to-end in production (job 4c0d7330, ~7s, real RSA-PSS UCCO, 34 completed) — the reasoner was the archetypal lily pad and it stands on rock. FILED 2026-07-31. SUPERSEDED 2026-07-21 by UCCA-TM-2026-07-21-B — no longer the current session baton; read the marked current baton first. Verifies to 52193b2a200d…, 11,610 B, 69 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-21-A.md
UCCA-TM-2026-07-20-B Session-close baton for 2026-07-20 (B) — CURRENT SESSION REFERENCE, read first at cold start. the auth-fronted submit is BUILT, DEPLOYED, and PROVEN (gate now demands a verified credential, stamps the verified client_id on the permanent row); the gate has its own permanent home submit.ucca.online (custo. FILED 2026-07-31. SUPERSEDED 2026-07-21 by UCCA-TM-2026-07-21-A — no longer the current session baton; read the marked current baton first. Verifies to d9de2b547030…, 10,772 B, 60 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-20-B.md
UCCA-TM-2026-07-20-A Session-close baton for 2026-07-20 (A) — CURRENT SESSION REFERENCE, read first at cold start. D1–D5 ruled and recorded; five ADRs (0007–0011) ratified + filed; the ground-landing that never committed finally landed (caught by a git read); the VET-leak audit done + verdicted (input door clean, fossils on. FILED 2026-07-20. SUPERSEDED 2026-07-20 by UCCA-TM-2026-07-20-B — no longer the current session baton; read the marked current baton first. Verifies to 135303a95e43…, 13,047 B, 86 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-20-A.md
UCCA-TM-2026-07-19-B Session-close baton for 2026-07-19 (B) — CURRENT SESSION REFERENCE, read first at cold start. the day the first engine capability went live and got minted. FILED 2026-07-31. SUPERSEDED 2026-07-20 by UCCA-TM-2026-07-20-A — no longer the current session baton; read the marked current baton first. Verifies to 782df26a95b7…, 10,873 B, 81 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-19-B.md
UCCA-TM-2026-07-19-A Session-close baton for 2026-07-19 (A) — CURRENT SESSION REFERENCE, read first at cold start. the day the engine came back into focus. FILED 2026-07-31. SUPERSEDED 2026-07-19 by UCCA-TM-2026-07-19-B — no longer the current session baton; read the marked current baton first. Verifies to 49e3556f6664…, 11,205 B, 69 lines. (row retro-registered 2026-08-02.) ground/UCCA-TM-2026-07-19-A.md
UCCA-RULING-OUTCOME-NUMBER-TYPE-2026-07-31 Ruling — outcome_number is typed in the throat's input contract. Filed and EXECUTED IN FULL — erratum, Seam 1, Seam 1b, Seam 2, replay — and until this row existed it was discoverable only by knowing its filename, though it had already changed the gate's accepted input and the reasoner's pre-seal fence and is cited by the frozen contract pack. Engine commits: 631a8254 (Seam 1) · bdef0163 (Seam 1b) · 255d70e7 (Seam 2) · 773043c7 (replay + mode=full) · 36f10692 (fixture). Docs: 01cdcd4c (the erratum) · fecbde92 (the filing). ⚠ Its own status: frontmatter is STALE IN THE BYTES, DELIBERATELY — it still reads UNFILED… Ruling 3 is a CONDITIONAL STOP, all of which has since happened. The bytes were not tidied after the ruling was acted on, because the digest is the identity; this row does not inherit that field.The census in its Ruling 3 undercounts: taken on 5 integer-carrying payloads where there are 9 — the four edit jobs (201e96df, 5a1485e5, 5fa1e639, 2e126e87, all 2026-07-19) fell outside a generation-only census. All four are client_id NULL, so they clear Ruling 3's own test and the ruling stands as taken; only the number in it is wrong.STILL OPEN, and NOT closed by this row: requirement_ref is typed in no frozen schema. The erratum declared outcome_number, one half of the pair assert_trace_covers and _trace_closes compare; that both are emitted in the same type is a by-construction property measured over 26 envelopes, not a contract. Owed into the erratum or v1.1. filed ✓ 2026-07-31 at fecbde92. Verifies to 72f920dd572a…, 11,897 B, 102 lines — re-derived from the committed object 2026-08-02, not taken from the request card's report, and cmp-identical to the project-root copy. Not crossed — engine-side; the document states NOTHING CROSSES. Not deployed — both seams committed and pushed, awaiting Tim's word. ⚠ REGISTER STATE NOT ASSIGNED, AND DELIBERATELY SO. UCCA-CARD-REQUEST-REGISTER-ROW-OUTCOME-NUMBER-RULING-2026-07-31 §2 reserves two judgements no executing seat may make: which lifecycle state applies — its type declaration is pre-proof while its enforcement is built, tested and replayed against 43 real artefacts but not deployed — and whether it is ADR-shaped at all, the ruling's own §6 flagging it as "plausibly ADR-shaped (Class G, mints on ratification)" and stating "This seat does not mint ADRs." Neither does this one. This row discharges the card's request by making the ruling discoverable; it mints nothing, and the state is Tim's to set. ground/UCCA-RULING-OUTCOME-NUMBER-TYPE-2026-07-31.md
UCCA-TM-2026-08-02 Session-close baton for 2026-08-02 — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THE FENCE GOT ITS LAW: FENCE-PROTOCOL-02 ran its full lifecycle — drafted on the fresh context H reserved, ruled, filed, carried and answered — and the revision-path thread closed on this house's side. FILED 2026-08-02 at 13a65b5 — SUPERSEDED 2026-08-02 by UCCA-TM-2026-08-02-B — no longer the current session baton; read UCCA-TM-2026-08-02-B first. Bytes untouched, still verify to dfc2b51f9b8c…, 14,920 B, 173 lines. Supersedes UCCA-TM-2026-08-01-H. Verifies to dfc2b51f9b8c…, 14,920 B, 173 lines. ⚠ Its frontmatter relates_to cites "the four unfiled directing artefacts named in §6's filing act", but the filing act is §4 item 7, not §6 — an internal cross-reference error, recorded here rather than fixed: the digest is the identity and a baton is not tidied after filing. ⚠ That item-7 expectation of five documents was wrong by three, and its own "the expectation yields to the glob" is what caught it — see the filing commit. Reconfirm ALL live state; do NOT assert live from this baton. ground/UCCA-TM-2026-08-02.md
UCCA-RULING-PUSH-ACT-CLOSE-AND-DOCKER-2026-08-02 Ruling record — the push act-close standing rule; Docker share surface unchanged; source-kill explicitly deferred. §1 mints the rule: any act containing a push ends with git status -sb, reported, and ahead ≠ 0 at act-close is a defect in the act, not a follow-upls-remote at the remote is the escalation when count and claim disagree. Origin: the four-hour window in which a container cache-bust commit was unreproducible from origin because a push was silently eaten by a 0-byte lock. §2 leaves Docker's share surface at macOS defaults — the safe removals don't touch the cause and the one that would (/Users) breaks suite 16's fixture bind mount and the ARM renders. §3 defers the real fix (dedicated share directory + fixture relocation) and ledgers it as deferred, because deferred ≠ done. FILED 2026-08-02 at 13a65b5. MINTED 2026-08-02 on Tim's word — governance convention, Class G per UCCA-ADR-LIFECYCLE-01 (mints on ratification). ⚠ The class letter is this seat's reading of the lifecycle vocabulary, not a value the ruling supplied — the ruling states MINTED and names a governance convention; if G is wrong the correction is one cell. Verifies to 7bc4d305f43b…, 3,933 B, 58 lines. Parts 2 and 3 are inaction recorded as decision — nothing deployed, no substrate change. ground/UCCA-RULING-PUSH-ACT-CLOSE-AND-DOCKER-2026-08-02.md
UCCA-FILING-BRIEF-CLOSE-PASS-AND-REGISTER-SQUARE-II-2026-08-02 Filing brief — the close pass and register-square II. Instrument — the baton's item-7 filing act, the Docker ruling's filing, the two FI-row repairs and the Sent-table backfill, in one ordered pass. EXECUTED 2026-08-02 — this pass. Its §0 derived-set rule is what turned an expected 7 into a filed 8, itself included: it could not name itself in its own expected list. FILED 2026-08-02 at 13a65b5 on the baton's item-7 filing act, which overrides the instrument-unfiled default for the documents that act reaches. Verifies to 4e0ae6eb2a2f…, 6,360 B, 99 lines. ground/UCCA-FILING-BRIEF-CLOSE-PASS-AND-REGISTER-SQUARE-II-2026-08-02.md
UCCA-FILING-BRIEF-REGISTER-SQUARE-2026-08-02 Filing brief — square the canon register. Instrument — enumerate the baton gap by glob, file the unfiled, register the unregistered, move the single-baton marker destroy-proof, mint the outcome_number row, repair the orphaned index row. EXECUTED 2026-08-02 at e828615 · f23f4c6 · d6ad912 · 87c64e6 · b29b172. Its expected 14 unregistered batons measured 34 — an older gap its 13-candidate probe never looked for. FILED 2026-08-02 at 13a65b5 on the baton's item-7 filing act, which overrides the instrument-unfiled default for the documents that act reaches. Verifies to c486d058c8fb…, 8,244 B, 121 lines. ground/UCCA-FILING-BRIEF-REGISTER-SQUARE-2026-08-02.md
UCCA-FILING-CARD-REVISION-PATH-SECOND-2026-08-02 Filing card — REVISION-PATH-SECOND: file, record, log. Instrument — file the carried crossing, record the carry, log the sequence inversion. EXECUTED 2026-08-02 at c98bfd9 · 8f609ee · 848f469. Its step 5 reserved FI-09 to Tim, who ruled log. FILED 2026-08-02 at 13a65b5 on the baton's item-7 filing act, which overrides the instrument-unfiled default for the documents that act reaches. Verifies to d7239874a9a2…, 4,078 B, 67 lines. ground/UCCA-FILING-CARD-REVISION-PATH-SECOND-2026-08-02.md
UCCA-CARD-INBOUND-REVISION-REPLY-AND-FI08-2026-08-02 Card — inbound filing + FI-08. Instrument — file RTOpacks' revision-path reply to canon/received/ and log the mis-routed relay instruction. EXECUTED 2026-08-02 at 131873d · fbbf4bd. ⚠ Its relates_to cites UCCA-RULING-RECEIPT-CHECK-SCOPE-2026-08-02; no such document exists — the ruling is dated 2026-08-01, and the index cites the one that exists. FILED 2026-08-02 at 13a65b5 on the baton's item-7 filing act, which overrides the instrument-unfiled default for the documents that act reaches. Verifies to 3d055684d7b4…, 5,401 B, 71 lines. ground/UCCA-CARD-INBOUND-REVISION-REPLY-AND-FI08-2026-08-02.md
UCCA-CARD-LOCK-SWEEP-AND-CARRY-RECORD-2026-08-02 Card — lock sweep, then the carry record. Instrument — clear the four stale index.lock files and record the FENCE-PROTOCOL-02 carry. EXECUTED 2026-08-02 at ce8130f. The sweep was the fifth occurrence of the Docker-VM lock pattern and the first measured as four locks from one event, not one. FILED 2026-08-02 at 13a65b5 on the baton's item-7 filing act, which overrides the instrument-unfiled default for the documents that act reaches. Verifies to e6ea9156c051…, 5,222 B, 74 lines. ground/UCCA-CARD-LOCK-SWEEP-AND-CARRY-RECORD-2026-08-02.md
UCCA-FILING-CARD-PROTOCOL-02-AND-INDEX-FIX-2026-08-02 Filing card — the PROTOCOL-02 filing and index fix. Instrument — complete the exchange-model carry record and file the ruled FENCE-PROTOCOL-02 proposal. EXECUTED 2026-08-02, the predecessor act to the lock-sweep card. FILED 2026-08-02 at 13a65b5 on the baton's item-7 filing act, which overrides the instrument-unfiled default for the documents that act reaches. Verifies to 48a85fc9d4ff…, 6,891 B, 98 lines. ground/UCCA-FILING-CARD-PROTOCOL-02-AND-INDEX-FIX-2026-08-02.md
UCCA-TM-2026-07-24-B-TECH Technical Time Machine (2026-07-24 build day) — CURRENT TECH REFERENCE. The load-bearing event: NORTHSTAR-01 → v1.1 "the declared claim" (Class G, UCCA-AMENDMENT-NORTHSTAR-HONESTY) + ADR-0014 (honesty grammar, ruled B pre-proof; finding-contract v2 measure-first-gated; frozen schema untouched). Built/banked this day: the Control Rail (first admin-only audited control action, R-RAIL-1), adversarial calibration (sealed per-element quotes + 14-trap set, 0% fabrication), the measure-first benchmark (PROBE_SUITES registry + console suite-selector + panel polish) with the first per-domain measurement (GLM-5.2 temp 0: defence-v1 100%/0.0%, v2 general 93.3%/0.0%, the one over-claim = EN388 inference), and the four widening suitesfive domain suites live (v1/v2/defence-v1 + defence-contrast/pharma/aviation/finance-v1; default stays v2). HEADs: engine 4c9b9c3 · surfaces b2af229 · infra 04806f2 · docs 365ca4c (moves on filing) — all clean + pushed. Owed: Tim runs the 4 new suites → 5-domain matrix + defence-contrast verdict; a 2nd Workers-AI model → clears ADR-0014; then the finding-schema-v2 build. A28 (Instruments 2/3 unconsumed) keystone-open. Account e5a98302; f95d4537 never; no fence crossing. Supersedes UCCA-TM-2026-07-24-A-TECH (filed, unregistered) and the voice of UCCA-TM-2026-07-22-A-TECH (whose engine-spine internals — F2/gate-poll/reasoner-CI/living-certificate/keys-A′/custody-cols — still stand). filed ✓ 2026-07-24 (authored + filed in-workspace by Alex, R-TM-1; sha256 f8c1c6f79ac4cdbaf118159d84924692bf820e6734bb00c26a55b5266db5b15e) COMPANION, NOT A BATON — never carries the session marker. Complements its session baton; does not supersede it. ground/UCCA-TM-2026-07-24-B-TECH.md
UCCA-TM-2026-07-22-A-TECH Technical Time Machine (2026-07-21/22 build sessions) — engine-spine internals current; voice superseded by UCCA-TM-2026-07-24-B-TECH 2026-07-24. Six units shipped, each proven live + minted: F2 GLM-5.2 priced by neurons · gate poll-auth (F3, credential+ownership on GET) · reasoner CI deploy (local Docker retired) · the living certificate (anchor-break auto-revocation, new job_type reverify) · keys-worker DB-scope A' (public worker off the spine store via internal ucca-status-reader) · custody columns migration 004 (R1 keystone). HEADs: engine f309e12 · docs d801a8c · infra 7b1dc34 · surfaces b162308 (untouched); all clean. Live: gate 9ef77a2f, keys e8efc800, reasoner CI-run 29906223487, status-reader 84b5138e; D1 jobs=19 cols/69 rows, ucco_status 1 (revoked 9a57fdce…). Open lanes: R2 5b (buildable), R3 VC-wiring (deferred, A'-preservation constraint), §8 token-split→narrow-ucca-deploy→1Password. Account e5a98302; f95d4537 never; no fence crossing. Cowork batons 21-B/22-A cite-only (off Alex's disk). filed ✓ 2026-07-22 (authored + filed in-workspace by Alex, R-TM-1; sha256 cadcf8d18e80d873a9216e037d60379044cfbef43311fc94f763662986ef7cf5) COMPANION, NOT A BATON — never carries the session marker. Complements its session baton; does not supersede it. ground/UCCA-TM-2026-07-22-A-TECH.md
UCCA-TM-2026-08-02-B Session-close baton for 2026-08-02 (B) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THE THREAD CLOSED AND THE FIRST JOB KNOCKED: the revision-path second ran its lifecycle, and RTOpacks asked for the credential that starts the first end-to-end job. FILED 2026-08-02 at 0bff9a1 — SUPERSEDED 2026-08-02 by UCCA-TM-2026-08-02-C — no longer the current session baton; read UCCA-TM-2026-08-02-C first. Bytes untouched, still verify to 5f6f7e8a72de…, 18,293 B, 77 lines. Supersedes UCCA-TM-2026-08-02. Verifies to 5f6f7e8a72de…, 18,293 B, 77 lines. Reconfirm ALL live state; do NOT assert live from this baton. ground/UCCA-TM-2026-08-02-B.md
UCCA-CARD-INBOUND-PAIR-AND-CREDENTIAL-READS-2026-08-02 Card — file the verified inbound pair, clear the phantom-receipt caveat, then the reads the credential reply needs. Instrument — two parts: part 1 files RTOP-CROSSING-SUBMISSION-CREDENTIAL-01 and RTOP-NOTICE-RECEIPT-WITHDRAWN-01 and clears the exchange-model caveat; part 2 is substrate reads only, generating nothing. EXECUTED 2026-08-02 at 7679e21 (part 1); part 2 produced a report, not commits. FILED 2026-08-02 at 0bff9a1 on the B baton's item-7 filing act. Verifies to ff7ca09a9017…, 6,146 B, 87 lines. ⚠ Its part-2 report is the evidence base for the credential reply this house now owes — and the load-bearing finding is that a live, unrevoked, unexpired submit-scope credential for client_id rtopacks already exists (rtopacks-prod-2026-08-01, expires 2027-01-28), against the inbound's premise that the key was "deliberately not reissued". Issuance is Tim's ruling and nothing was minted. The caveat cleared in three places, not the one the card named. ground/UCCA-CARD-INBOUND-PAIR-AND-CREDENTIAL-READS-2026-08-02.md
UCCA-FILING-BRIEF-CLOSE-B-AND-COMPANION-NORMALISE-2026-08-02 Filing brief — the B baton's filing act plus the pinned TECH-companion normalisation. Instrument — one ordered pass: companion normalisation, the filing act, register rows, and the marker move. EXECUTED 2026-08-02 — this pass. FILED 2026-08-02 at 0bff9a1, itself included by its own §0 derived-set rule, which it could not anticipate. ⚠ Its act-one honesty note was WRONG in this house's favour and the enumeration overturned it: it reported that its own read "could not reproduce a two-table split"; the split was real — 2 companion rows in the Canon table, 11 in Ground — and 9 of 13 rows carried no companion form at all. ⚠ It arrived as a PASTE with no digest published, unlike the five instruments before it; its doc_id, final line and headings were checked against the on-disk file before execution, and this filing establishes its seal. Verifies to d707b439a5bb…, 6,804 B, 96 lines. ground/UCCA-FILING-BRIEF-CLOSE-B-AND-COMPANION-NORMALISE-2026-08-02.md
UCCA-REPORT-CREDENTIAL-READS-2026-08-02 Report — the substrate reads the credential reply rests on. Gate mechanics as deployed (two refinements the client's filed contract does not carry); course_code measures zero in the deployed gate, withdrawing RUNNABLE-STATE §5.9 as a current-state claim; the four Ask-4 statuses; and the T-6 population read from the counter's own source. ⚠ Its load-bearing finding: a live, unrevoked, unexpired submit credential for client_id rtopacks already existed, against the request's premise that the key was "deliberately not reissued". ✅ DISPOSED 2026-08-02 on Tim's revoke-and-re-mint ruling: rtopacks-prod-2026-08-01 revoked 2026-08-02, never delivered, superseded by the ruled re-mint — row retained, revocation being a field and not a delete; replacement rtopacks-prod-2026-08-02 minted, submit, 180-day expiry, not yet delivered. Exactly one live credential exists for the client at any moment, verified after the act. ⚠ brief_in_prompt is not a field and never was — zero by content search and by git log -S across all refs, re-verified first-hand at the execution seat. filed ✓ 2026-08-02 at 2ae2579. Verifies to 10f24b014867…, 11,451 B, 180 lines. Live reads 2026-08-02, read method named per figure, rows_written 0 throughout, account pin verified, no token value selected, read, echoed or logged. Produced by UCCA-CARD-INBOUND-PAIR-AND-CREDENTIAL-READS-2026-08-02 part 2, which specified a report and no commits; filed so the crossing citing it does not rest on unfiled root bytes. ground/UCCA-REPORT-CREDENTIAL-READS-2026-08-02.md
UCCA-TM-2026-08-02-C Session-close baton for 2026-08-02 (C) — CURRENT SESSION REFERENCE, read first at cold start. THE WINDOW THE FIRST JOB'S CREDENTIAL GOT ITS CLEAN CHAIN: the credential reply filed, ruled, carried and confirmed byte-exact both directions; the credential revoked and re-minted; FENCE-PROTOCOL-02 ratified on RTOpacks' second. FILED 2026-08-02 at 914d434 — SUPERSEDED 2026-08-02 by UCCA-TM-2026-08-02-D — no longer the current session baton; read UCCA-TM-2026-08-02-D first. Bytes untouched, still verify to 4b6f21682a3f…, 15,553 B, 70 lines. Supersedes UCCA-TM-2026-08-02-B. Verifies to 4b6f21682a3f…, 15,553 B, 70 lines. Reconfirm ALL live state; do NOT assert live from this baton. ground/UCCA-TM-2026-08-02-C.md
UCCA-CARD-CREDENTIAL-RESPONSE-FILE-AND-REMINT-2026-08-02 Card — file the credential reply and its evidence, then execute the revoke-and-re-mint ruling. Instrument — four acts: two filings, the carry-record repair, and the D1 credential operation. EXECUTED 2026-08-02 at 2ae2579 · 239df07 · fabfcb5, plus the D1 write (no commit). FILED 2026-08-02 at 914d434.THIS IS THE DOCUMENT FI-11 RECORDS AS HAVING CROSSED THE FENCE — an engine-side instrument, typed "Not a fence document", that travelled on the reply's relay leg. RTOpacks hold it immutably and acted on nothing in it; filing it here means both houses hold the same bytes under the same doc_id, so the incident row points at something checkable from either side. Verifies to e9f95f4910ee…, 7,356 B, 92 lines. ground/UCCA-CARD-CREDENTIAL-RESPONSE-FILE-AND-REMINT-2026-08-02.md
UCCA-CARD-INBOUND-TRIO-AND-PROOF-PROMOTION-2026-08-02 Card — the inbound trio, proof promotion, incident logging, filing. Instrument — five acts: file three inbounds, log FI-10 and FI-11, promote both carries from attested to proven, discharge the close-C filing debt with the marker move, and file the thread-close crossing before its carry. EXECUTED 2026-08-02 — this pass. Its act-4 expectation of four documents matched the glob exactly, the first expectation this house has not had to overturn in a full day of derived-set passes. Verifies to 3f1af371c724…, 5,880 B, 82 lines. ground/UCCA-CARD-INBOUND-TRIO-AND-PROOF-PROMOTION-2026-08-02.md
UCCA-SLIP-CREDENTIAL-DROP-2026-08-02 Delivery slip — the out-of-band handover of the rtopacks-prod-2026-08-02 submission credential, by disk drop, in Tim's hands. The mechanism §2 of the credential reply committed to, executed. FILED 2026-08-02 at 914d434. Verifies to d1c3e9384df7…, 4,724 B, 71 lines. ✅ NO CREDENTIAL VALUE APPEARS IN IT, OR IN ANY ARTEFACT IN THIS THREAD — the constraint RTOpacks set at their Ask 2, adopted verbatim and holding in both directions. Their RTOP-NOTICE-CREDENTIAL-COLLECTED-01 (3dcf51625067…) closes the delivery loop, label only. ground/UCCA-SLIP-CREDENTIAL-DROP-2026-08-02.md
UCCA-TM-2026-08-02-D Session-close baton for 2026-08-02 (D) — CURRENT SESSION REFERENCE, read first at cold start. The window the first end-to-end job in the fence's history ran, failed at 393.8 s, and came back as a crossing with five findings and three asks. FILED 2026-08-02 — SUPERSEDED 2026-08-03 by UCCA-TM-2026-08-02-E — no longer the current session baton; read UCCA-TM-2026-08-02-E first. Bytes untouched, still verify to cc5ff505166b…, 9,074 B, 57 lines. Supersedes UCCA-TM-2026-08-02-C. Verifies to cc5ff505166b…, 9,074 B, 57 lines. Reconfirm ALL live state; do NOT assert live from this baton. ground/UCCA-TM-2026-08-02-D.md
UCCA-TM-2026-08-02-E-EXEC Execution-seat companion for 2026-08-02 (E) — COMPANION, NOT A BATON. The deployed substrate fingerprint, the day's defect ledger, and what only a seat with substrate access established — written because the drafting seats close their batons without reach to Cloudflare, D1, R2, the container image or the gate logs. FILED 2026-08-02 at 1c79b1b. Companion, not a baton — never carries the session marker. Complements UCCA-TM-2026-08-02-D; supersedes nothing. Verifies to e26af3eb0efb…, 11803 B, 156 lines. ⚠ AMENDED IN PLACE 2026-08-02 after first filing at 1c79b1b — the original omitted §2a entirely: the control job ran at 11:35:01Z and COMPLETED, sixty-five minutes before the companion was written, and it was filed on an 11:11Z row read without re-checking at write time. The seat's own defect, recorded in §2a rather than quietly patched. Never crossed, no other house holds it, home ground record — replace-in-place binds nothing. ⚠ Carries the four-identifier deployed fingerprint, which is in no repo — including the gate version_id the runtime stamped on the probe's own log lines, the only check that proves same code served the probe. Records that gate bundle byte counts are NOT comparable across pulls (random multipart boundary) and that container observability is empty, so the R2 diagnostic is the only autopsy after the gate hands off. ground/UCCA-TM-2026-08-02-E-EXEC.md
UCCA-REPORT-PROBE-READS-2026-08-02 Report — the Act-2 read pass on the first end-to-end job. The §4 bound live in v37 (read by executing inside the image by digest); A-1's diagnostic record verbatim; A-2's counters NULL and the instrument defect owned as ours; the deployed poll status vocabulary; and the GO-PROBE reconciliation. FILED 2026-08-02 at 82854f7. Verifies to 079e34f65cee…, 12,586 B, 213 lines. Read-only: rows_written 0 throughout, no deploy, no job submitted, no job row touched.Found a SECOND accepted job on the byte-identical payload, undeclared0ac575ff…, 34.8 s earlier, counters (6, 6), failed at assemble. Whose fire it was is NOT ESTABLISHED and is asked directly, not inferred. ⚠ Corrects the filed status set three ways, not the one RTOpacks foundcomplete vs deployed completed hangs a conformant client silently. ground/UCCA-REPORT-PROBE-READS-2026-08-02.md
UCCA-REPORT-ASSEMBLE-FAILURE-READ-2026-08-02 Report — deep read of the assemble failure on job 0ac575ff. What JOB_ENVELOPE_ASSEMBLY_ERROR hit is NOT RECOVERABLE, and the reason is a defect in how this engine records failure detail. FILED 2026-08-02 at 82854f7. Verifies to 58fbd01c7fae…, 8,349 B, 140 lines. Read-only; job rows untouched. ⚠ JobFailure.__init__ calls super().__init__(code), so str() of one is the bare code, and with_retry's tail falls back to str(last) — so the class built to carry structured failure detail is the one whose detail vanishes. All nine raise sites pass a cause; none survived. Same window, same payload: the non-JobFailure failure kept its full message. Two branches eliminated on bytes; the rest left open and not guessed. ground/UCCA-REPORT-ASSEMBLE-FAILURE-READ-2026-08-02.md
UCCA-TM-2026-08-02-E Session-close baton for 2026-08-02 (E) — CURRENT SESSION REFERENCE, read first at cold start. THE BATON THAT CLOSES THE DAY THE ENGINE COMPLETED ITS FIRST JOB: the probe crossing received and answered on deployed bytes, the second accepted job found by our logs and owned by their correction, four instrument defects reported and none fixed. FILED 2026-08-03 at the close-E pass — SUPERSEDED 2026-08-03 by UCCA-TM-2026-08-03-A — no longer the current session baton; read UCCA-TM-2026-08-03-A first. Bytes untouched, still verify to d04b9a6ad478…, 12,209 B, 57 lines. Supersedes UCCA-TM-2026-08-02-D. Verifies to d04b9a6ad478…, 12,209 B, 57 lines. Reconfirm ALL live state; do NOT assert live from this baton. ground/UCCA-TM-2026-08-02-E.md
UCCA-TM-2026-08-03-A-EXEC Execution-seat cold-start for 2026-08-03 — COMPANION, NOT A BATON. The live substrate re-read at write time, the open loop the seat left in the sent index and owns, the inbound correction awaiting filing, and the close-E pass the marker was one baton behind on. FILED 2026-08-03. Companion, not a baton — never carries the session marker. Complements UCCA-TM-2026-08-02-E; supersedes nothing. Verifies to 05a16a09a238…, 13,509 B, 213 lines. ⚠ Every figure re-read AT WRITE TIME, because the previous day's closing record was filed on a row read 89 minutes stale and had to be amended.Records that a fingerprint without its derivation is not checkable — the D1 schema signature recomputed over column names gave 6665cff3… against the published 9a23db1261f90cf3…, reading as drift when the schema was unchanged; the method is now stated with the number. Its §2 self-reported the missing sent-index row that this pass repaired; its §7 measured the root backlog at 68 unfiled documents, named and deferred. ground/UCCA-TM-2026-08-03-A-EXEC.md
UCCA-REPORT-FOLLOWUP-READS-2026-08-03 Report — the two follow-up reads. Read A locates the cause-less JobFailure link: it does not. Read B attributes the two overlapping jobs to instances: not retained. FILED 2026-08-03. Verifies to 925875919620…, 11,200 B, 169 lines. Read-only: rows_written 0 throughout, no deploy, no job submitted, job rows untouched. Deployed code parsed and executed inside the v37 image by digest, never repo HEAD. ⚠ READ A — NOT LOCATED, six shapes eliminated on bytes: :174's cause carries literal text and cannot go falsy; 24 JobFailure constructions app-wide by ast, zero without a cause, zero falsy, .cause never reassigned; the double-loaded-module isinstance failure tested live and refuted (same class object); rollout lag refuted (v37 served 22 h before the job); no non-JobFailure carries the code. This forces the repair into the tail itself — it must stop trusting causes to be truthy — rather than a point fix. ⚠ Corrects this seat's own prior report: UCCA-REPORT-ASSEMBLE-FAILURE-READ-2026-08-02 says nine raise sites; the ast count is eight, and its own table listed eight. Substance unaffected. ⚠ READ B — NOT RETAINED, with every source and its retention named; second independent confirmation of zero reasoner/container observability events. Established instead that the two jobs were concurrent, not serial. ⚠ A THIRD INSTRUMENT BLINDNESS, found unasked: the declared probe recorded ZERO cost-ledger rows while failing on a returned provider body; the success-path-only explanation is refuted (42 rows across 28 failed jobs historically). A concurrency-attribution hypothesis is offered and explicitly not established — one observation, no control, no instance visibility, the same standard this house applied to RTOpacks' scale claim. ground/UCCA-REPORT-FOLLOWUP-READS-2026-08-03.md
UCCA-TM-2026-08-03-A Session-close baton for 2026-08-03 (A) — CURRENT SESSION REFERENCE, read first at cold start. THE BATON THAT CLOSES THE FENCE'S FIRST COMPLETE DAY UNDER ITS OWN FULL FORM: every crossing byte-proven in both directions, and the first inbound whose digest travelled with its carry and verified on arrival. FILED 2026-08-03 — CURRENT SESSION BATON, read first at cold start. Supersedes UCCA-TM-2026-08-02-E. Verifies to f80b41e7a08c…, 15,467 B, 58 lines. Its execution-seat companion is UCCA-TM-2026-08-03-A-EXEC (05a16a09…, filed 7554899) — a companion, not a baton, carrying the deployed fingerprint that exists in no repo. Reconfirm ALL live state; do NOT assert live from this baton. ground/UCCA-TM-2026-08-03-A.md

Dead — retracted, never filed: UCCA-RTOPACKS-NEEDS-01. Drafted this session, then retracted under FENCE-PROTOCOL-01 §2 (authorship-stays-home): the engine must not author a client's requirements. Recorded here only so it is not re-attempted. See UCCA-FENCE-ADOPTION-01.

Strategy — true for now

doc_id title status path
UCCA-STRATEGY-01 open-standard sequencing, pricing, positioning, pitch architecture to write

Decisions — append-only ADR log (canon series)

adr_id title status path
ADR-0001 Name the manufactured object UCCO; retire CCO minted (F, verified 2026-07-01 — /ns/ucco/v1 on disk) decisions/canon/ADR-0001-ucco-naming.md
ADR-0002 The gate is domain-neutral; specialisation lives in the adapter F+F — MINTED 2026-07-03 (remedy verified: deployed input path gate-neutral + worlds-free; proof job 0dda7509; course-shape located outside the gate by ADR-0005) decisions/canon/ADR-0002-gate-neutrality.md
ADR-0003 Two entities, one link minted (F, verified 2026-07-01 — corporate fact) decisions/canon/ADR-0003-two-entities.md
ADR-0004 The engine spine runs on Cloudflare MINTED (F) 2026-07-03 — proof job 0dda7509 ran gate→engine→signed-envelope on the deployed CF spine; the engine is off disk. Mint annotation 2026-07-04 (Class B): max_instances=2 held through the wedge + its fix (cured by slot release, not by raising the cap) decisions/canon/ADR-0004-cloudflare-runtime.md
ADR-0005 The v1 content payload is the client's shape (course-shaped fields = ADAPTER, not gate) minted (G — ratified 2026-07-03 by Tim's ruling; formalises UCCA-RULING-ENVELOPE-SHAPE-01). ✎ v1.1 ID-stability clarification 2026-07-18 (G — ratified, cross-fence authorised): a HELD piece (spliced verbatim from an approved baseline, not re-generated) RETAINS its module_id/block_id/question_id; the "new version ⇒ new IDs" clause governs REGENERATED pieces only. Additive x-id-stability-clarification-v1_1 key on the §4.1 schema (engine commit 7137e26, check_schema OK) — not a re-freeze, shape unchanged, enables CAP-1 option (a). Authorised by RTOP-RULING-CAP1-IDFORK-2026-07-18 (received copy, crossed-body sha256 6b33ef99…) under Tim's concurrent-crossing ruling (fence-incidents FI-04); slip UCCA-SLIP-CAP1-V1_1-CLARIFICATION-2026-07-18. Cross-ref UCCA-FEASIBILITY-READ-RTOPACKS-BRIEF-2-2026-07-18NOT YET ON DISK (pending; Tim to file or drop the ref). No code built (assemble_edit / lineage / diff gate wait on a separate brief). ✎ 2026-07-19: CAP-1 (the capability this clarification enabled) is now built + Class-B minted on the live spine — see UCCA-CAP1-MINT-2026-07-19. decisions/canon/ADR-0005-envelope-content-shape.md
ADR-0006 Slot release on job completion; sleepAfter fence superseded for this purpose MINTED (B) 2026-07-04 — ruled on the P1 burst-deviation escalation (Option A + C robustness); proven P1b (103b3ae3·4c590523·55810eb3, handoff in seconds); supersedes the seam's F1/F2-only ruling. Deployed 0.1.2-slotrelease decisions/canon/ADR-0006-slot-release.md
ADR-0007 Envelope: universal claims block + client-shaped payload block (clarifies ADR-0005, does not override) minted (G — ratified 2026-07-20 by Tim) decisions/canon/ADR-0007-claims-payload-split.md
ADR-0008 UCCO subject = obligation–material relation, never the actor. FOUNDATION-01 alignment RESOLVED (moot) 2026-07-20 (UCCA-SLIP-CANON-FIXUP Option 1): §1/§2 already state the subject principle; no wording change owed; the prior HELD 'amendment' is withdrawn as mis-attributed. minted (G — ratified 2026-07-20 by Tim) decisions/canon/ADR-0008-ucco-subject.md
ADR-0009 Pure throat + open standard; adapters client-owned (operationalises ADR-0002; Brief 2 locates the fused adapter) minted (G — ratified 2026-07-20 by Tim) decisions/canon/ADR-0009-adapter-placement.md
ADR-0010 Retention: permanent record / deletable content + hash tombstone; three-mode client-selectable custody selector (Engine holds / Client holds / Both — fingerprint retained in all three) — ✎ amended 2026-07-20 (Tim D4 refinement). Scopes the permanence law (not an amendment). §7 'never content bodies' re-cross flagged (v1.1 contract change, owed to Tim, NOT carried). minted (G — ratified 2026-07-20 by Tim; amended 2026-07-20) decisions/canon/ADR-0010-retention.md
ADR-0011 Assertion scope: counts yes, judgment never; the yellow flag minted (G — ratified 2026-07-20 by Tim) decisions/canon/ADR-0011-assertion-scope.md
ADR-0012 Engine client-credential model: per-client key + client_id (gate-supported today); issuance/roll/revocation operated CENTRALLY by UCCA — no client self-service (UCCA must hold the revocation kill-switch); delivered via a UCCA-operated customer control panel (to build), manual operator issuance until then minted (G — ratified 2026-07-21 by Tim) decisions/canon/ADR-0012-credential-model.md
ADR-0013 Anchor fence v1.1 — "verbatim" refined to verbatim-modulo-canonicalisation (NFC, typographic folding, whitespace-collapse; never NFKC/case-fold/strip) + a 12-char admissibility floor; monotonicity split: the floor is version-gated at reverify so no pre-v1.1 seal is retroactively revoked. Full ruling record in the Ground table minted (G — ratified 2026-07-23 by Tim, on verdict UCCA-VERDICT-ANCHOR-HARDENING-2026-07-23) decisions/canon/ADR-0013-anchor-fence-verbatim-v1.1.md
ADR-0014 The declared claim (honesty grammar) — every finding declares its basis; strictness is a client-set adapter policy; principle ratified as NORTHSTAR-01 §6 (v1.1); the finding-contract v2 build is measure-first-gated. Companion: ADR-0015 (content). Full ruling record in the Ground table ruled (B — pre-proof 2026-07-24; finding-contract v2 build gated on the measure-first widening) decisions/canon/ADR-0014-declared-claim-honesty-grammar.md
ADR-0015 TRACED / NOT_YET_TRACED claim semantics — the claim's content. What a finding ASSERTS, as distinct from ADR-0014's mechanics of how it is qualified. TRACED = a byte-verified verbatim anchor responsive to this element of the compiled obligation, on the claim's declared basis, relative to the compilation and its enumerated leaf-set — and nothing more, with four standing named exclusions; it NEVER asserts the obligation is met, satisfied or complied with. NOT_YET_TRACED = an honest gap in the trace, never failure or non-compliance. Ratifies the unratified 2026-07-19 scoping (UCCA-TRIUMVIRATE-UNIVERSALITY-TEST-01); blind-corroborated 4/4 volunteered. Discharges the standing landmine that ADR-0002 alone cannot answer the verdict-neutrality objection. Companion to ADR-0014 — 0014 ruled B pre-proof (mechanics, measure-first-gated), 0015 is ratified Class G (content). Frozen findings contract v1 untouched. ratified 2026-07-26 (Class G) — NORTHSTAR-01 v1.2; ruling UCCA-AMENDMENT-NORTHSTAR-TRACED-SEMANTICS-2026-07-26 decisions/canon/ADR-0015-traced-claim-semantics.md (ruling record also at ground/UCCA-AMENDMENT-NORTHSTAR-TRACED-SEMANTICS-2026-07-26.md; ✎ file authored 2026-07-27 at the register-hygiene sitting (Tim's ruling); previously recorded row-only per the 2026-07-26 relay's §5)

The canon ADR series (ADR-000N) is deliberately separate from the pre-existing infrastructure ADR series (adr-001adr-005 under decisions/). Two series, two homes, no number collision.

Received — cross-fence copies (never promoted to home canon)

Filed 2026-07-01, bodies byte-verified against the relay; RECEIVED COPY header prepended (only edit).

doc crossing status path
FENCE-PROTOCOL-01 (received copy) #1 — the fence protocol filed ✓ canon/received/FENCE-PROTOCOL-01.md
FENCE-RULING-RECORD-01 (received copy) the two rulings (their record) filed ✓ canon/received/FENCE-RULING-RECORD-01.md
RTOPACKS-ENGINE-BRIEF-01 (received copy) the brief the engine assessed (§5 filled) filed ✓ canon/received/RTOPACKS-ENGINE-BRIEF-01.md
RTOPACKS-RESPONSE-TO-ASSESSMENT-01 (received copy) the agreed answers (crossed version) filed ✓ canon/received/RTOPACKS-RESPONSE-TO-ASSESSMENT-01.md
RTOPACKS-ACK-CONTRACT-PACK-01 (received copy) ack of the pack — closes §6 freeze condition filed ✓ canon/received/RTOPACKS-ACK-CONTRACT-PACK-01.md
RTOPACKS-CORRECTION-01 (received copy) the D-3 correction (C-3/C-4) filed ✓ canon/received/RTOPACKS-CORRECTION-01.md
RTOPACKS-REVIEW-CONTENT-PAYLOAD-01 (received copy) §4.1 review — RENDERABLE + 4 changes + Q-B4.1 filed ✓ canon/received/RTOPACKS-REVIEW-CONTENT-PAYLOAD-01.md
RTOPACKS-RESPONSE-MIGRATE-02-PHASE-6-01 (received copy) Phase-6 answer Q1–Q4 — clearance GRANTED (retire retained DBs+workers, backup last; DNS + rtopacks.com.au EXCLUDED); .migration-exports/ cull green-lit. sha256 4ce1abb3… verified filed ✓ canon/received/RTOPACKS-RESPONSE-MIGRATE-02-PHASE-6-01.md
RTOPACKS-CORRECTION-02 (received copy) corrects Q1 enrichment row — enrich-sync is LIVE (3/4 functions have live successors); KN-enrichment dormant, qual-enrichment released into the retirement unit. sha256 4f6909ef… verified filed ✓ canon/received/RTOPACKS-CORRECTION-02.md
UCCA-CROSSING-INTAKE-PHASE-6-01 (home intake note) relay facts + filing record for the crossing; digest typo settled by bytes (our note was wrong: …a8bd) filed ✓ canon/received/UCCA-CROSSING-INTAKE-PHASE-6-01.md
UCCA-CROSSING-CONFIRM-PHASE-6-01 (home confirm note) RTOpacks filed our request their side (Tim testimony) — closes the crossing's housekeeping loop filed ✓ canon/received/UCCA-CROSSING-CONFIRM-PHASE-6-01.md
RTOPACKS-CONFIRM-PAIR-RECEIPT-01 (received) RTOpacks filed the pack+schema pair verbatim, digests MATCH; $id erratum landed; block-encoding return CLOSED → ledger zero both directions (scope note, ORDER-06: this closure covers the pack/schema pair only — not the C-6 or intake-presentation threads) filed ✓ canon/received/RTOPACKS-CONFIRM-PAIR-RECEIPT-01.md
RTOPACKS-REPLY-C6-CHASE-01 (received) RTOpacks' reply on the C-6 thread — asserts Phase-6 answered/corrected/confirmed; asks us to verify against our received/; flags the action-vs-parked inconsistency. ⟨ALEX⟩ placeholders crossed unfilled (property of the received bytes) filed ✓ (ORDER-05 Step 0) — sha256 9e382618…; thread OPEN canon/received/RTOPACKS-REPLY-C6-CHASE-01.md
RTOPACKS-ACK-INTAKE-PRESENTATION-01 (received) RTOpacks' ack — cover received, instrument NOT received; presentation incomplete; requests re-send of the complete packet. ⟨ALEX⟩ placeholders crossed unfilled filed ✓ (ORDER-05 Step 0) — sha256 2084484…; thread CLOSED 2026-07-04 — resolution packet crossed + verbally acked (UCCA-ATTEST-RESOLUTION-ACK-01); INTAKE-01 presentation COMPLETE canon/received/RTOPACKS-ACK-INTAKE-PRESENTATION-01.md
UCCA-ATTEST-RESOLUTION-ACK-01 (relay attestation) closing artefact — resolution packet delivered + acknowledged (VERBAL at relay, no authored reply, none expected); FI-01 pattern (relay attests where no authored crossing exists) filed ✓ 2026-07-04 — closes the resolution-packet thread + the INTAKE-01 presentation; VERIFY-BEFORE-CROSS satisfied (sent-log entry present) canon/received/UCCA-ATTEST-RESOLUTION-ACK-01.md
QR1A-samples (attachment) §4.1 samples supplement (9 files, real corpus) filed ✓ (manifest-verified) canon/received/QR1A-samples/
RTOP-CROSSING-THREAD-CLOSE-RECEIPT-01 received copy — their receipt closing the credential thread, and the queue it leaves standing, the 6,200 §4-bound-in-v37 answer among the items owed filed ✓ 2026-08-02, byte-verbatim, origin prefix kept. Verifies to be8a17f09061…, 4,170 B, 59 lines — digest published with the carry and verified independently on this device before the copy was read as the artefact. Respond-never-redline: not one byte edited. canon/received/RTOP-CROSSING-THREAD-CLOSE-RECEIPT-01.md
RTOP-CROSSING-PROBE-RESULT-01 received copy — THE FIRST END-TO-END JOB IN THE FENCE'S HISTORY. Job ef4ce088-50db-46b3-a320-13e862314e24, unit UEEEL0039, accepted 202 at 09:26:24Z with brief_received: true, terminal 09:32:57Z JOB_STEP_RETRY_EXHAUSTED at 393.8 s. Five findings (F-1 a failed job is not actionable from its response · F-2 queued returned by the poll endpoint and absent from the filed status set · F-3 the first time-to-fail figure either house holds · F-4 both filed refinements confirmed deployed · F-5 the course_code withdrawal verified by execution) and three asks (diagnostic record · job-row counters · enumeration amendment) filed ✓ 2026-08-02, byte-verbatim, origin prefix kept. Verifies to beedd1e518bc…, 4,520 B, 50 lines. ⚠ Carry-leg defect their side, conceded — the FIFTH instance of the FI-10 pattern: digest published in their DISPATCHES register (c673e931) before carry, omitted from the carry message; held under §3.3 and closed same-hour on independent computation both sides. ⚠ ✅ AMENDED BY RTOP-CROSSING-PROBE-DECLARATION-CORRECTION-01 (5a4c6c446992…), 2026-08-02: its §1 "one generation job" corrects to two accepted submissions, one operator-intended; the undeclared job 0ac575ff… is owned as their fire and the incident is ruled their side. ⚠ BOTH FACTS STAND — the original bytes remain PROVEN and the content is corrected. The correction is the amending record; nothing here is swapped or withdrawn, and this row's proven-digest claim is untouched. Their §4 scale hypothesis is NOT established and is quarantined as theirs — one observation, no control, no step visibility; this register draws no conclusion from it. canon/received/RTOP-CROSSING-PROBE-RESULT-01.md
RTOP-CROSSING-PROBE-DECLARATION-CORRECTION-01 received copy — RTOpacks correcting their own filed crossing under form. Answers UCCA-CROSSING-PROBE-ANSWERS-01 §5: the undeclared job 0ac575ff… was their fire, a paste that ran past a prose line into the fire command; interrupted before their manifest was written, which is why their enumeration missed it and our gate logs did not. Incident ruled their side. filed ✓ 2026-08-03, byte-verbatim, origin prefix kept, received under full §3.3 form. Verifies to 5a4c6c446992…, 4,662 B, 35 lines. Its §5 asks nothing — no reply owed. It also confirms our probe-answers crossing received under form with the digest confirmed both sides. canon/received/RTOP-CROSSING-PROBE-DECLARATION-CORRECTION-01.md
RTOP-CROSSING-CONTROL-RESULT-01 received copy — the first completed job between the houses, quoted whole: job 5ac5cc7e…, UEEEL0045, 86.6 s, envelope sealed and byte-stable; their conformance reading; five envelope-contract observations; five asks filed ✓ 2026-08-03, byte-verbatim, origin prefix kept. Verifies to 00382156d5d3…, 6,612 B, 62 lines — ⚠ computed at this house, NOT published with the carry: an FI-10 instance on the leg. Cure: RTOpacks' confirming digest, appended here when it crosses back. ✅ Promotes UCCA-TM-2026-08-02-E §2.5's client-side facts from attested to artefact-backed.§3 proves our completed amendment live in the success direction and measures the pre-amendment vocabulary's cost: 2,405.9 s · 226 attempts · completed ×217 — matching this house's independent gate-log count of 226, computed before the crossing arrived.§2 establishes our canonicalisation by reproduction (compact JSON, sorted keys) — flagged for the queued contract amendment. §5's asks unanswered here, by the card.FI-10 ON THIS LEG: CURED 2026-08-03. RTOpacks confirmed their filed original computes 00382156d5d3140357bad9b720e8c05715cabcaf650232b082df021ba0eb195f · 6,612 B · 62 lines — byte-exact match with our received copy, re-derived here from the committed object before recording this. Two houses, independent computation, agreement on all three measures. The defect was that no digest travelled with the carry; the cure is that neither house needed it to — which is the same cure that has held on every instance of this pattern. Their confirmation reached us through Tim's relay; if a receipt artefact follows, it is cited here rather than replacing this line. ✅ AND NOW UNDER FORM, 2026-08-03: the same three figures — 00382156… · 6,612 B · 62 lines, byte-exact match — are stated in RTOpacks' consolidated carry block (item 2). The caecd05 provenance caveat (relayed-not-artefact) is discharged to the extent the carry-block form provides; both citations are kept, because a fact confirmed twice by different routes is worth more than a fact whose first route is overwritten. canon/received/RTOP-CROSSING-CONTROL-RESULT-01.md
RTOP-CROSSING-FOURCLASS-FIXTURE-01 received copy — opens the fixture exchange for the four-class expansion; five asks FX-1–FX-5 (corpus transport · version minting · CI evidence form · the D element · two standing items touched not replaced) filed ✓ 2026-08-03, byte-verbatim, origin prefix kept. Verifies to 9cbfed15c57d…, 6,769 B, 47 lines. ✅ THE FIRST INBOUND WHOSE DIGEST TRAVELLED WITH THE CARRY AND VERIFIED ON ARRIVAL — the cured form working; leg clean, no FI-10 instance.REV 2 GOVERNS; rev 1 (51d2c993…) never crossed and is void by their own final line. A rev-1 copy exists in ~/Downloads/ on this machine (6,438 B) and was identified and deliberately not filed — recorded so no later pass files it by name. Their §1 quotes our filed position back as the constraint their builder now enforces in code — the interlock is mutual: no four-class production send until the consumption fixture passes in both houses' CI. Answers to FX-1–FX-5 are owed at this house's clock, not given here. canon/received/RTOP-CROSSING-FOURCLASS-FIXTURE-01.md
RTOP-CROSSING-PROBE05-RESULT-01 received copy — the solo re-fire's formal result: job 104eb3e4… failed; what the fire eliminated, with scope; and the formal A-3 extension filed ✓ 2026-08-03, byte-verbatim, origin prefix kept. Verifies to 4d918154d43c…, 6,996 B, 49 lines. ✅ Digest travelled WITH the carry and verified byte-exact — second instance of the full form, second clean leg, no FI-10 caveat.§3: our-side concurrency eliminated as a NECESSARY cause of the 6-element failures, run under this house's re-attestation of 02:17:09Z — with their own two bounds stated: the attestation preceded the fire by 50 minutes, and n=1 eliminates necessity only. ⚠ Branches 2/3 not adjudicable — because our async failure surface returns failure_code alone. The discriminator is engine-side step telemetry: the instrument-repair brief's business, and a defect on our side of the fence.§4 is the SOLE vehicle of the A-3 extension to 104eb3e4… and supersedes the quarantined fragment (channel defect ledgered both houses; figures checked consistent against §1–§2). Cure complete on this filing. Receipt owed §1–§4; one A-3 answer covering all three failed jobs joins the answers crossing at this house's clock — not answered here. canon/received/RTOP-CROSSING-PROBE05-RESULT-01.md

See canon/received/ for the received-copy discipline (respond-never-redline). ~~All three previously-pending received copies are now filed; no crossings outstanding.~~ CORRECTED 2026-07-04 (ORDER-06, per ORDER-05 finding rows 7/9/12): this line was memory-born and is false. Two inbound replies are openRTOPACKS-REPLY-C6-CHASE-01 (9e382618…) on the C-6 thread and RTOPACKS-ACK-INTAKE-PRESENTATION-01 (2084484…, presentation incomplete: instrument not received) on the intake-presentation thread. Our two sent crossings (UCCA-CROSSING-C6-CHASE-01, UCCA-CROSSING-INTAKE-PRESENTATION-01) were absent from canon/sent/ until filed retroactively under ORDER-06 (fence-incident FI-01). Corrections tracked by VERIFY-BEFORE-CROSS.

✎ CORRECTED 2026-07-10: this "two inbound replies are open" count is now stale — only the C-6 inbound remains open. The intake-presentation half (RTOPACKS-ACK-INTAKE-PRESENTATION-01, 2084484…) closed 2026-07-04 per rows :172/:202 — the resolution packet crossed and was verbally acked (UCCA-ATTEST-RESOLUTION-ACK-01), INTAKE-01 presentation COMPLETE. Current in-flight count = 1: RTOPACKS-REPLY-C6-CHASE-01 (9e382618…) on the C-6 thread, ball in UCCA's court (verify against received/; resolve the action-vs-parked flag). Verified by row cross-check 2026-07-10.

Sent — cross-fence originals (UCCA authored; copies cross out)

Filed 2026-07-01, manifest-verified (shasum -c). Originals of record; copies cross to RTOpacks.

doc_id carries status path
UCCA-FENCE-RULING-RECORD-01 conformer/gate custody + warranty boundary (Ruling 1, Ruling 2) filed ✓ (copy crosses back) canon/sent/UCCA-FENCE-RULING-RECORD-01.md
UCCA-ASSESSMENT-RTOPACKS-BRIEF-01 engine's assessment of RTOpacks' brief (R-, D-, B-*) filed ✓ (copy crossed) canon/sent/UCCA-ASSESSMENT-RTOPACKS-BRIEF-01.md
UCCA-ASSESSMENT-RTOPACKS-BRIEF-01-ADDENDUM-01 engine's answer to brief §5 (A-*) filed ✓ (copy crossed) canon/sent/UCCA-ASSESSMENT-RTOPACKS-BRIEF-01-ADDENDUM-01.md
UCCA-ACK-CORRECTION-01 ACK of RTOPACKS-CORRECTION-01 (C-3/C-4) filed ✓ (copy crosses back) canon/sent/UCCA-ACK-CORRECTION-01.md
UCCA-CORRECTION-01 the Dec-2025 run correction (attested-history wording) — RTOpacks acked filed ✓ (crossed) canon/sent/UCCA-CORRECTION-01.md
UCCA-RESPONSE-CONTENT-PAYLOAD-01 four §4.1 deltas + Q-B4.1; declares the freeze filed ✓ (crossed) canon/sent/UCCA-RESPONSE-CONTENT-PAYLOAD-01.md
UCCA-REQUEST-MIGRATE-02-PHASE-6-01 Phase-6 confirmation request (4 Qs) — retire retained UCCA-account RTOpacks DBs+workers ~~FILED, NOT CROSSED 2026-07-03 — Tim carries; fence quiet~~ · ✎ CORRECTED 2026-07-10: the "not crossed" status is superseded by bytes — RTOpacks answered and the answer is filed at canon/received/RTOPACKS-RESPONSE-MIGRATE-02-PHASE-6-01.md (clearance GRANTED, sha256 4ce1abb3… verified). The memory-born "not crossed / awaiting" premise is recorded false in FI-01. Retirement execution remains gated on C-6 (thread OPEN — see UCCA-RETIREMENT-UNIT-BRIEF-01 §2 and register row for RTOPACKS-REPLY-C6-CHASE-01). Filed crossing doc unchanged. canon/sent/UCCA-REQUEST-MIGRATE-02-PHASE-6-01.md
UCCA-CORRECTION-PHASE-6-PREMISE-01 correction to our own Phase-6 request premise — the "retained ~450 MB rtopacks-db" was a documentation phantom; asks whether anything in the clearance changes ✎ DISPOSITIONED 2026-07-10 (ruled, Tim): NEVER CARRIED — status NOT CROSSED. Drafted 2026-07-03 (commit cf2bbfd), filed to canon/sent/, but per the fence log it has no register row, no FILING-NOTE, no carried/handed marker, and no received-side reply (forensic read 2026-07-10). Superseded in practice by the forensic doc (UCCA-FORENSIC-RETAINED-DBS-01) + the C-6 thread. A non-receipt confirmation line will ride the C-6 response. Nothing carried unilaterally; PREMISE-01 body unchanged. canon/sent/UCCA-CORRECTION-PHASE-6-PREMISE-01.md
UCCA-CROSSING-NOTE-PACK-SCHEMA-01 outbound cover: v1.0 contract pack + content-payload schema (the owed pair) — pack sha256 ad0c08ca1bd2…, schema 7e2703f17b99… HANDED TO TIM 2026-07-03 to carry to RTOpacks; sources in docs-site/strategy/ canon/sent/UCCA-CROSSING-NOTE-PACK-SCHEMA-01.md
UCCA-CROSSING-C6-CHASE-01 chase on the C-6 / Phase-6 request (memory-born premise — see FI-01) RETROACTIVE — sent 2026-07-03, filed under ORDER-06; bytes crossed before filing (incident FI-01); sha256 181caec5… canon/sent/UCCA-CROSSING-C6-CHASE-01.md
UCCA-CROSSING-INTAKE-PRESENTATION-01 cover presenting ratified UCCA-INTAKE-01 (cover only — the instrument did NOT accompany it; see FI-01c) RETROACTIVE — sent 2026-07-03, filed under ORDER-06; crossed before filing + ahead of its C-6 hold (early release ruled at relay, recorded in FI-01); sha256 753e3436…. Resolution packet (cover + instrument + digest) prepared separately canon/sent/UCCA-CROSSING-INTAKE-PRESENTATION-01.md
UCCA-CROSSING-RESOLUTION-NOTE-01 resolution cover — completes the intake presentation (attaches ratified UCCA-INTAKE-01 instrument + digest, fixing FI-01c's omission) filed ✓ 2026-07-04 — cover sha256 3d6667f2…; instrument 5f6eccb6…. CROSSED + delivered 2026-07-04 (Tim, sole relay); acknowledged VERBAL at relay (RTOpacks satisfied, no paperwork authored, none expected) → thread CLOSED; closing artefact UCCA-ATTEST-RESOLUTION-ACK-01 canon/sent/UCCA-CROSSING-RESOLUTION-NOTE-01.md
UCCA-CROSSING-REVISION-PATH-SECOND-01 this house's second on the revision path, answering RTOP-CROSSING-REVISION-PATH-REPLY-01 (a9670112…) — corpus home seconded; the item-1 constraint accepted as a joint position (the type declaration must explain the 16/8↔3-module mechanism, not merely pick a type); item 2's negatives accepted verbatim; item 4's fixture halves both accepted and their catch owned CARRIED 2026-08-02, THEN filed at c98bfd9 — inverted order, FI-09. Verifies to 14e37b5a79a3…, 10,586 B, 140 lines, derived from the committed object. ⚠ FI-01-class ordering defect — relay preceded filing, against VERIFY-BEFORE-CROSS (Class G); logged as FI-09 on Tim's ruling 2026-08-02. No byte or verification damage: the digest was published with the carry and the bytes were frozen at approval, so what crossed and what is filed are provably identical — the distinction from UCCA-CROSSING-AB-SCOPE-ACCEPT-01, where no digest went with the carry. Governance track untouched (7566e2ef… runs separately per FENCE-PROTOCOL-02 §4). Nothing owed from this house in this thread. canon/sent/UCCA-CROSSING-REVISION-PATH-SECOND-01.md
UCCA-CROSSING-FENCE-PROTOCOL-02-PROPOSAL-01 the FENCE-PROTOCOL-02 proposal — §3.3 disk-first inbound, §4 tracks, §5 thread concurrency, §6 split-confirmation form, §8 annex filed ✓ · CARRIED 2026-08-02. Verifies to 7566e2ef7f3d…, 15,253 B, 202 lines — derived from the committed object 2026-08-02, matching the sent index. Approved by Tim 2026-08-02, all five PROPOSED provisions as drafted, no amendments.GOVERNANCE TRACK — the one governance crossing in flight, per its own §4. NOT RATIFIED AND NOT MINTED: its §10 sets ratification (RTOpacks seconding + Tim) as the minting event. canon/sent/UCCA-CROSSING-FENCE-PROTOCOL-02-PROPOSAL-01.md
UCCA-CROSSING-EXCHANGE-MODEL-RESPONSE-01 this house's response on the exchange model — answers RTOP-CROSSING-EXCHANGE-MODEL-POSITION-01 (92fc135070b2…), filed in received/ filed ✓ · CARRIED 2026-08-01. Verifies to 970a4659b501…, 12,521 B, 170 lines — derived from the committed object 2026-08-02, matching the sent index. Filing preceded relay. RTOpacks verified the received bytes exact on all three measures. ✅ CAVEAT CLEARED 2026-08-02 — resolved by WITHDRAWAL, not receipt: the awaited RTOP-RECEIPT-EXCHANGE-MODEL-RESPONSE-01 was filed their side 2026-08-01 and never carried, and is withdrawn as superseded (RTOP-NOTICE-RECEIPT-WITHDRAWN-01, fbbc51811ecd…). Nothing further owed inbound. The acknowledgement of our bytes stays TM-attested — the withdrawal disposes of the missing document, it does not make the acknowledgement artefact-proven. canon/sent/UCCA-CROSSING-EXCHANGE-MODEL-RESPONSE-01.md
UCCA-CROSSING-AB-SCOPE-ACCEPT-01 this house's acceptance of the A/B scope filed ✓ · CARRIED 2026-08-01. Verifies to 5eb6bef10e02…, 6,947 B, 96 lines — derived from the committed object 2026-08-02, matching the sent index. ⚠ FI-01 ORDERING DEFECT: filing did NOT precede relay. It crossed before any copy existed on this machine, and no digest was published with the carry, so for that interval this house could not have proved identity for a document it had already sent. The distinction from FI-09, where the digest did go. canon/sent/UCCA-CROSSING-AB-SCOPE-ACCEPT-01.md
UCCA-CROSSING-CEILING-FIGURE-AND-BRANCH-01 the ceiling measurement and the branch it selects filed ✓ · CARRIED 2026-08-01. Verifies to e9a04b588597…, 4,872 B, 68 lines — derived from the committed object 2026-08-02, matching the sent index. The ceiling measurement and the branch it selects. canon/sent/UCCA-CROSSING-CEILING-FIGURE-AND-BRANCH-01.md
UCCA-FINDING-FORWARD-ENVELOPE-ENUMERATION-01 the forward envelope enumeration finding filed ✓ · CARRIED 2026-08-01. Verifies to a2cff18e24de…, 6,639 B, 101 lines — derived from the committed object 2026-08-02, matching the sent index. Receipt confirmed BYTE-EXACT by RTOpacks — their independently computed figure agrees to the byte and the line. canon/sent/UCCA-FINDING-FORWARD-ENVELOPE-ENUMERATION-01.md
UCCA-CROSSING-TIER1-RESPONSE-01 the answer to RTOP-CROSSING-TIER1-ANSWER-01 — their §5a answered on ADR-0005; the forward contract handed over corrected after two of this house's own claims were withdrawn rather than sent; the application domain-drift flag; and **what submits the payload declared openly as NOT ESTABL filed ✓ · CARRIED 2026-07-31. Verifies to 31d6ebc6dade…, 17,434 B, 140 lines — derived from the committed object 2026-08-02, matching the sent index. RTOpacks' independently computed digest matches exactly; they filed it before reading it. ⚠ Whether OUR sha256 was published with this carry is OPEN — an earlier claim that it was is withdrawn. canon/sent/UCCA-CROSSING-TIER1-RESPONSE-01.md
UCCA-CROSSING-RPL-CAPABILITY-ANSWER-01 the engine-capability answer to RTOpacks' RPL query — evidence→competency reasoning is a new mode on the backward core, not a core re-engineer (bytes-hardened on the 2026-07-06 read-only diagnosis recon; ADR-0005 forward course-shape did not leak backward) filed ✓ · CARRIED 2026-07-31. Verifies to 721ad42dc6ca…, 8,666 B, 134 lines — derived from the committed object 2026-08-02, matching the sent index. FILED 2026-07-06, CARRIED 2026-07-31 — 25 days uncarried.Its own status: frontmatter reads DRAFT and is STALE IN THE BYTES, DELIBERATELY — read UCCA-NOTE-RPL-STATUS-FIELD-2026-07-31 before the field. canon/sent/UCCA-CROSSING-RPL-CAPABILITY-ANSWER-01.md
UCCA-CROSSING-ENGINE-STATE-RESPONSE-01 the answer to RTOP-ENGINE-STATE-REQUEST-2026-07-30 — yes to the runnable-state document, with the honest limit that most of what was asked is live substrate the drafting layer is blind to, so a recon pass with live reads comes first; names the convergence with UCCA's own Window 3; restates the non filed ✓ · CARRIED 2026-07-31. Verifies to 3a124d02f2f1…, 16,441 B, 97 lines — derived from the committed object 2026-08-02, matching the sent index. Filing preceded relay. It crossed first and alone, against the one-parcel ruling — FI-07. canon/sent/UCCA-CROSSING-ENGINE-STATE-RESPONSE-01.md
UCCA-CROSSING-TIER1-QUESTIONS-ANSWER-01 the answer to RTOP-CROSSING-TIER1-RESPONSE-ACK-01 on Q1 through Q4course_code; the credential, rotated rather than merely named; validation on the forward path; and the two empty-outcome payloads CARRIED — PROVEN ON BYTES 2026-08-02, both houses agreeing independently on all three measures (RTOP-CROSSING-CREDENTIAL-RESPONSE-RECEIPT-01, bd386116ac7f…, §2). ⚠ Carried with no record kept and no digest published — FI-10. The proof does not undo the record defect. History follows: filed ✓ Verifies to 9d1c6a2ecbea…, 20,022 B, 143 lines — derived from the committed object 2026-08-02, matching the sent index. REV 2. NOT CARRIED — awaiting Tim's carry. ⚠ Rev 1 (089d951e…) was filed then replaced in place before carry for one false capability sentence; replace-in-place is safe only where never crossed is verified from the sent index each time. Publish 9d1c6a2e…, not 089d951e…. canon/sent/UCCA-CROSSING-TIER1-QUESTIONS-ANSWER-01.md
UCCA-ENGINE-RUNNABLE-STATE-2026-07-31 the engine's current runnable state, answering RTOP-ENGINE-STATE-REQUEST-2026-07-30 — what the engine takes, what it emits, how it is invoked and by whom, what it has actually been run on, what breaks, timing and cost. Carries one real UCCO envelope verbatim at §2.2 (1,939 B, sha256 50715 | ✅ **CARRIED — PROVEN ON BYTES 2026-08-02**, both houses agreeing independently on all three measures (RTOP-CROSSING-CREDENTIAL-RESPONSE-RECEIPT-01,bd386116ac7f…, §2). ⚠ **Carried with no record kept and no digest published — FI-10.** The proof does not undo the record defect. **History follows:** **filed ✓** Verifies to495148b7db0c…, 34,870 B, 324 lines — **derived from the committed object 2026-08-02**, matching the sent index. **REV 6. NOT CARRIED — awaiting Tim's carry.** Carries one real UCCO envelope verbatim at §2.2 (1,939 B,50715e26…), bit-for-bit unchanged across every revision. ⚠ **Revs 1 and 2 were each filed then replaced in place before carry.** **Publish ONLY495148b7….** |canon/sent/UCCA-ENGINE-RUNNABLE-STATE-2026-07-31.md`
UCCA-CROSSING-SUBMISSION-CREDENTIAL-RESPONSE-01 the answer to RTOpacks' submission-credential request — the credential disposition, the out-of-band delivery mechanism and terms, the gate contract confirmed with two refinements, and the four Ask-4 statuses in one reply filed ✓ 2026-08-02 at 2ae2579 · CARRIED 2026-08-02 — filing preceded relay.Received byte-exact both directions (their §1 = our filed object). ⚠ No digest published with the carry on the relay leg — the FI-10 pattern recurring on the next carry.FI-11: an engine-side card travelled on this leg and should not have. Verifies to 82588ae182a7…, 15,301 B, 171 lines; digest publishes WITH the carry. REV 3, FINAL — revs 1–2 replaced in place, never filed, never crossed. Tim ruled its three PROPOSED marks 2026-08-02 as drafted. ✅ Rev 3 repairs a transcribed digest and a carry premise this house's own index contradicted, both caught before filing. Evidence base UCCA-REPORT-CREDENTIAL-READS-2026-08-02 (10f24b014867…). canon/sent/UCCA-CROSSING-SUBMISSION-CREDENTIAL-RESPONSE-01.md
UCCA-CROSSING-CREDENTIAL-THREAD-CLOSE-01 the credential thread closing proven — their three carries confirmed on bytes from our side, our reply's bytes confirmed to theirs, and the ceiling re-carry travelling with it filed ✓ 2026-08-02 at 914d434 · NOT CARRIED — awaiting Tim's carry. Filing precedes relay. Verifies to 9a4bb87ecda1…, 7,249 B, 97 lines; digest publishes WITH the carry.Per FI-11 the outbound attach-set is named in the executing seat's report and is exactly two files — this crossing and UCCA-CROSSING-CEILING-FIGURE-AND-BRANCH-01 (e9a04b588597…, bytes unchanged). Nothing else travels on this leg. canon/sent/UCCA-CROSSING-CREDENTIAL-THREAD-CLOSE-01.md
UCCA-CROSSING-PROBE-ANSWERS-01 the probe's answers on deployed bytes — the §4 bound live in v37; A-1's diagnostic record verbatim; A-2's counters NULL with the instrument defect owned as ours; A-3 answered plus two defects past it; the second accepted job on the byte-identical payload stated as bytes with one direct question filed ✓ 2026-08-02 at 1ae6d42 · CARRIED 2026-08-02 under §3.3 · RECEIPTED BYTE-EXACT. Filing preceded relay. Receipt is not testimony: RTOP-CROSSING-PROBE-DECLARATION-CORRECTION-01 (5a4c6c446992…) records it "received under form, digest confirmed both sides" and quotes ecf8d74b…/11,055/150 — matching our filed object on all three measures, computed independently in the other house. ✅ Its §5 question is ANSWERED by that same correction: the undeclared job was their fire. ⚠ Its row in canon/sent/index.md was MISSING until 2026-08-03 — see that file; the executing seat's own FI-10-class defect, repaired and recorded. Verifies to ecf8d74bdeb1…, 11,055 B, 150 lines; digest publishes WITH the carry per ratified §3.3. Five marks ruled by Tim 2026-08-02 as drafted — zero PROPOSED marks remain in the body. ⚠ §4 corrects the filed status set three ways, not the one RTOpacks found: queued missing (their F-2), complete vs the deployed completed — which hangs a conformant client silently where queued only breaks a strict validator loudly, and which they could not have found because their job failed — and revoked missing. ⚠ §3 owns an instrument defect as ours: brief_modules_* are structurally NULL for any job failing inside generate, because the capture line sits after the raising call — contradicting the filed value grammar that says (None,None) means no run happened. §6 offers bytes bearing on their §4 scale hypothesis and draws no conclusion — the hypothesis stays theirs and quarantined. Evidence base UCCA-REPORT-PROBE-READS-2026-08-02 (079e34f65cee…), unfiled — a register row is owed for it. canon/sent/UCCA-CROSSING-PROBE-ANSWERS-01.md
UCCA-CROSSING-CONTROL-RECEIPT-AND-SUBSTRATE-REATTEST-01 the receipt for RTOP-CROSSING-CONTROL-RESULT-01 under form, and the four substrate fingerprints re-attested live for the pending solo re-fire filed ✓ 2026-08-03 · CARRIED 2026-08-03 · RECEIPTED BYTE-EXACT. Filing preceded relay; digest published with the carry per §3.3. RTOpacks' consolidated carry block of 2026-08-03 (item 3) states received, verified byte-exact their side (a530bbd05447be…, 4,069 B, 47 lines, their independent computation), and filed. ⚠ Provenance: the confirmation travelled in the carry block, not yet as a filed receipt artefact — a receipt artefact is cited alongside if one later crosses. Verifies to a530bbd05447…, 4,069 B, 47 lines; digest publishes WITH the carry. Approved by Tim 2026-08-03 as drafted; bytes frozen at approval.§1 names an FI-10 instance on their leg (no digest travelled inbound) and asks for a one-line confirmation as the cure; our received row stays computed-here until it arrives. ✅ §2 states the D1 fingerprint's derivation with the value and shows the counter-example — the lesson that a figure without its method is not checkable, now proposed as a convention for both houses. ✅ Records the 226/226 independent agreement on the status-vocabulary cost. canon/sent/UCCA-CROSSING-CONTROL-RECEIPT-AND-SUBSTRATE-REATTEST-01.md
UCCA-CROSSING-PROBE05-RESULT-RECEIPT-01 the receipt for RTOP-CROSSING-PROBE05-RESULT-01 (4d918154…) — §1–§4 under form, the A-3 extension accepted into the combined answers crossing with the not-retained posture stated, their §5 receiving nothing by its own terms filed ✓ 2026-08-03 · NOT CARRIED — awaiting Tim's carry. Filing precedes relay (VERIFY-BEFORE-CROSS, Class G). Verifies to 2a2a48fe337f…, 5,196 B, 36 lines; digest publishes WITH the carry. Bytes frozen at Tim's approval and re-verified on disk before filing. canon/sent/UCCA-CROSSING-PROBE05-RESULT-RECEIPT-01.md

See canon/sent/ for the sent-original discipline.

Contract surfaces (docs-site)

doc_id title status path
UCCA-CONTRACT-PACK-01 Input-Path Contract Pack (engine API boundary; ADR-0002 Class B proof vehicle) v1.0 FROZEN 2026-07-02 ✓ — stamp cites QR1A samples · RTOPACKS-ACK (§6) · RTOPACKS-REVIEW · UCCA-RESPONSE docs-site/docs/strategy/ucca-input-path-contract-pack-v0.1.md
§4.1 content-payload schema v1 frozen intent-typed shape (module/block/question IDs; provenance→§4.3; fossils dropped) filed ✓ (frozen with the pack) docs-site/docs/strategy/ucca-content-payload-schema-v1.json

Crossed to RTOpacks 2026-07-02 — the stamped pack + v1 schema were carried for the conformer build (~/Downloads/ucca-stamp-crossing-2026-07-02/). One open return: RTOpacks' block-encoding confirmation (modules[].blocks[]), a v1.1 clarification if it diverges — not a re-freeze.

Capture / scaffolding

doc_id title status path
UCCA-BUILD-LEDGER build ledger — A/T-number assignment authority (assumption + keystone series) filed ✓ (living, non-canon) — convention minted (G, ratified 2026-07-27 by Tim at the register-hygiene sitting) canon/build-ledger.md
UCCA-CAPTURE-01 session capture, naming rulings, filing plan filed ✓ (non-canon; verbatim) canon/UCCA-CAPTURE-01.md
UCCA-FOSSIL-LEDGER fossil ledger — yellow-tape record of the archaeological dig filed ✓ (living, non-canon) canon/fossil-ledger.md
UCCA-FENCE-INCIDENTS fence-incident ledger — FENCE-PROTOCOL-01 departures (UCCA side) filed ✓ (living, ORDER-06) canon/fence-incidents.md
UCCA-RULING-VERIFY-BEFORE-CROSS-01 fence state comes only from a same-session read of the fence log; filing precedes relay filed ✓ — minted (G, ratified 2026-07-04) (ORDER-06 Step 4; earned by FI-01) decisions/canon/UCCA-RULING-VERIFY-BEFORE-CROSS-01.md

Narrative — historical artefact (frozen)

title status path
the-gate-whitepaper on disk; needs dated header noting naming resolved to UCCO-per-(b) (do not rewrite) narratives/the-gate-whitepaper.md

Living register. Update whenever a document is filed, written, or superseded, and flip a ruling's state to minted when it reaches proof. Never claim ✓ without a file.